SQL Injection Testing

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides payloads for Out-of-Band (OOB) data extraction that target non-whitelisted external domains such as attacker.com and attacker-server.com through DNS and HTTP requests.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data (target URLs and parameters), presenting an attack surface for indirect prompt injection.
  • Ingestion points: Target web application URL, injectable parameters (URL params, form fields, cookies, headers) as described in Phase 1.
  • Boundary markers: No specific delimiters or instructions to ignore malicious embedded commands within the target data are defined.
  • Capability inventory: The skill generates complex SQL injection payloads but does not involve direct shell command execution or local file system operations on the agent's host.
  • Sanitization: No data validation or sanitization routines are specified for the input data before payload generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — SQL Injection Testing