sqlmap

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with sqlmap’s real purpose, but that purpose is offensive security. It enables an AI agent to perform active SQLi exploitation, data extraction, file access, and OS-level actions against targets, so the overall security risk is high even without evidence of malware or deceptive data routing.

Confidence: 92%Severity: 86%
SecurityMEDIUM
references/tamper-guide.md

The supplied fragment is offensive SQL injection and WAF-bypass documentation rather than malicious package code. It contains no evident embedded malware or autonomous data theft, but it explicitly provides actionable procedures for unauthorized database dumping, credential extraction, arbitrary file access, webshell deployment, and remote command execution. Use should be restricted to authorized testing environments.

Confidence: 99%Severity: 90%
Audit Metadata
Analyzed At
Sep 15, 2026, 10:00 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fsqlmap%2F@d46ee3c38699a664759859e87e42402465ce90c44ada038e8b170cb0224c47a3
Security Audit — socket — sqlmap