nosql-injection

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides a Python script template using the 'requests' library designed to automate blind data extraction from target databases by enumerating field values using regex operators.\n- [COMMAND_EXECUTION]: Outlines procedures for achieving command execution on target infrastructure, specifically describing how to create a web shell via Redis configuration commands (CONFIG SET) and how to abuse MongoDB's JavaScript environment.\n- [REMOTE_CODE_EXECUTION]: Documents the use of the MongoDB '$where' operator to execute arbitrary JavaScript logic on the database server, enabling logic bypass and time-based extraction oracles.\n- [DYNAMIC_EXECUTION]: Details the injection of query operators and the manipulation of aggregation pipelines to dynamically alter query behavior and bypass security controls.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:15 PM
Security Audit — agent-trust-hub — nosql-injection