hunt-nosqli
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous
curlcommands intended for vulnerability scanning against a user-defined$TARGETvariable. It also includes local shell commands for validating the skill's own structure. - [EXTERNAL_DOWNLOADS]: Includes instructions to install
nosqlmapusingpip3.nosqlmapis a well-known open-source tool for automating NoSQL injection testing. - [REMOTE_CODE_EXECUTION]: Documents methods for achieving remote code execution on a target system through $where JavaScript injection in MongoDB or configuration manipulation in Redis via SSRF. These are described as security testing objectives rather than malicious actions performed by the skill itself.
- [DATA_EXFILTRATION]: Describes techniques for extracting data from a target database, such as character-by-character enumeration using regex or time-based blind injection. These actions are scoped to the intended security auditing use case.
Audit Metadata