webapp-sqlmap
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The assets/ci-config-template.yml file contains a command to download and execute a setup script for the tfsec security tool from Aqua Security's official GitHub repository.
- [COMMAND_EXECUTION]: The skill provides patterns for executing sqlmap with advanced flags that enable remote file system manipulation and OS command execution on target servers.
- [PROMPT_INJECTION]: The skill is designed to process external data sources such as HTTP request files and target URLs, which constitutes an ingestion point for untrusted content that could potentially trigger indirect prompt injection.
Audit Metadata