exploit-sqli
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous examples for executing
sqlmapandcurlto identify and exploit SQL injection vulnerabilities. These are standard security testing practices. - [EXTERNAL_DOWNLOADS]: The documentation references official repositories for
sqlmap(github.com/sqlmapproject/sqlmap), which is a well-known and trusted security tool. - [REMOTE_CODE_EXECUTION]: The
boolean_sqli_tester.pyscript usesurllib.requestto perform HTTP requests against user-provided URLs. While this involves interacting with remote servers, the behavior is local to the agent's environment and intended for vulnerability scanning, not remote code execution on the host. - [DATA_EXFILTRATION]: While SQL injection can be used for exfiltration of database data from a target, the skill itself does not contain patterns for exfiltrating data from the agent's host or user environment to an unauthorized third party.
Audit Metadata