command-injection-rce - Command Injection to RCE Proof
Verify suspected OS command injection using OAST callbacks and demonstrate follow-on impact safely.
Tags
Updated: 2026-09-16Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Confirm shell metacharacter behavior
- Verify execution via OAST callback
- Demonstrate safe follow-on impact
- Report command injection finding
Inputs
- Suspected target parameters
- Recorded HTTP requests
- OAST canary domain
Outputs
- Critical finding report
- Saved proof note
- Updated plan status
Requirements
- Access to OAST service
- Allowed security testing tools
