SQL Injection Testing

Fail

Audited by Gen Agent Trust Hub on Apr 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous payloads for executing arbitrary SQL commands, including system-level procedures like xp_dirtree and LOAD_FILE which can interact with the underlying host system or network.
  • [DATA_EXFILTRATION]: The skill includes techniques for out-of-band data exfiltration, providing payloads designed to send sensitive database information to external, hardcoded attacker-controlled domains such as attacker.com and attacker-server.com.
  • [PROMPT_INJECTION]: The skill metadata and core purpose explicitly instruct the agent to perform offensive actions such as bypassing authentication and exploiting database query vulnerabilities, which may override standard AI safety guidelines.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 15, 2026, 06:11 PM
Security Audit — agent-trust-hub — SQL Injection Testing