Expression Language Injection skill: what it does and how to install it
Guides security testing of Java expression evaluators across Spring, Struts2, Confluence and JSP/JSF applications.
Summary generated from the skill's documentation.
Install
$ npx skills add yaklang/hack-skills --skill expression-language-injectionRun it in a terminal. If your agent is already running, start a new session so it picks the skill up.
About this skill
What it does. Guides testing of Java expression evaluators by using arithmetic probes to identify SpEL, OGNL or Java EL, then mapping the framework and error messages to relevant payloads. It covers Spring, Struts2, Confluence and JSP/JSF, including sandbox bypasses, actuator route abuse, CVE examples and command-output techniques.
When to use it. Use it to assess attacker-controlled expressions in Java applications and distinguish EL injection from template injection. It is not intended for Jinja2, FreeMarker or Twig template-engine testing; route those cases to an SSTI guide.
History
Repo stars
2.4k
Tracking since . A chart appears once there are 7 days of data.
Stars are counted for the whole repository, which holds 10 skills.
Installs
3.3k
Tracking since . A chart appears once there are 7 days of data.
Installs via skills.sh
Similar skills
- Writing SkillsGuides creating, editing and testing skills before they are deployed.
- Webapp TestingTests local web applications with Playwright: verify frontend behaviour, debug the UI, capture screenshots and read browser logs.
- Security Best PracticesReviews code against security best practices for its language and framework, and suggests improvements.