sqlmap
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill is internally consistent with sqlmap’s real purpose, but that purpose is offensive security. It enables an AI agent to perform active SQLi exploitation, data extraction, file access, and OS-level actions against targets, so the overall security risk is high even without evidence of malware or deceptive data routing.
The supplied fragment is offensive SQL injection and WAF-bypass documentation rather than malicious package code. It contains no evident embedded malware or autonomous data theft, but it explicitly provides actionable procedures for unauthorized database dumping, credential extraction, arbitrary file access, webshell deployment, and remote command execution. Use should be restricted to authorized testing environments.