SQL Injection Testing
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill provides payloads for Out-of-Band (OOB) data extraction that target non-whitelisted external domains such as
attacker.comandattacker-server.comthrough DNS and HTTP requests. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data (target URLs and parameters), presenting an attack surface for indirect prompt injection.
- Ingestion points: Target web application URL, injectable parameters (URL params, form fields, cookies, headers) as described in Phase 1.
- Boundary markers: No specific delimiters or instructions to ignore malicious embedded commands within the target data are defined.
- Capability inventory: The skill generates complex SQL injection payloads but does not involve direct shell command execution or local file system operations on the agent's host.
- Sanitization: No data validation or sanitization routines are specified for the input data before payload generation.
Audit Metadata