SQL Injection Testing
Fail
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The instructions include specific SQL payloads designed for Out-of-Band (OOB) data extraction, referencing external domains such as "attacker-server.com" and "attacker.com" for exfiltration via DNS and HTTP protocols.
- [COMMAND_EXECUTION]: The skill requires the agent to utilize external exploitation tools like SQLMap and Burp Suite to perform automated vulnerability testing and request manipulation.
- [PROMPT_INJECTION]: The skill's description and core workflow instruct the agent to bypass security controls, including authentication forms and login verification systems, which overrides standard safety guidelines regarding unauthorized access.
Recommendations
- AI detected serious security threats
Audit Metadata