Skip to main content
expression-language-injectionby yaklang.io ProjectDevelopmentGitHub stars: 2.4k

Expression Language Injection skill: what it does and how to install it

Guides security testing of Java expression evaluators across Spring, Struts2, Confluence and JSP/JSF applications.

Summary generated from the skill's documentation.

Install

$ npx skills add yaklang/hack-skills --skill expression-language-injection

Run it in a terminal. If your agent is already running, start a new session so it picks the skill up.

About this skill

What it does. Guides testing of Java expression evaluators by using arithmetic probes to identify SpEL, OGNL or Java EL, then mapping the framework and error messages to relevant payloads. It covers Spring, Struts2, Confluence and JSP/JSF, including sandbox bypasses, actuator route abuse, CVE examples and command-output techniques.

When to use it. Use it to assess attacker-controlled expressions in Java applications and distinguish EL injection from template injection. It is not intended for Jinja2, FreeMarker or Twig template-engine testing; route those cases to an SSTI guide.

History

Repo stars

2.4k

Tracking since . A chart appears once there are 7 days of data.

Stars are counted for the whole repository, which holds 10 skills.

Installs

3.3k

Tracking since . A chart appears once there are 7 days of data.

Installs via skills.sh

Similar skills