SQLMap Database Penetration Testing
Fail
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for executing high-risk SQLMap commands, including the use of
--os-shellto obtain an interactive operating system shell and--os-cmdto execute arbitrary commands on the target server. - [DATA_EXFILTRATION]: The skill is designed to automate the extraction of sensitive database content, including full table dumps via
--dump, specific credential extraction forusernameandpasswordcolumns, and password hash collection using the--passwordsflag. - [REMOTE_CODE_EXECUTION]: The inclusion of
--file-writeand--file-destflags enables the agent to upload files, such as web shells, to the remote target, facilitating persistent access and remote code execution. - [CREDENTIALS_UNSAFE]: The skill demonstrates methods for accessing sensitive system files, specifically citing the retrieval of
/etc/passwdvia the--file-readparameter. - [PROMPT_INJECTION]: The skill presents a significant attack surface for indirect prompt injection by processing untrusted external data.
- Ingestion points: Target URLs, Burp Suite request files (
-r), log files (-l), and bulk URL lists (-m) provided by users. - Boundary markers: Absent; there are no instructions to use delimiters or warnings to ignore embedded content in the processed data.
- Capability inventory: Shell execution via
sqlmapsubprocess calls. - Sanitization: Absent; the skill does not instruct the agent to validate or sanitize external inputs before interpolating them into shell commands, which could allow a malicious user to trigger command injection on the agent's host environment.
Recommendations
- AI detected serious security threats
Audit Metadata