exploiting-sql-injection-with-sqlmap

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/agent.py

This module is not a passive library; it is an offensive automation harness that executes sqlmap against a user-supplied target and can enumerate databases/tables and dump table contents, then persist results to disk. It trusts a locally discovered sqlmap binary without integrity checks and forwards sensitive attacker-controlled inputs (including cookie and tamper). No obfuscation is present, but the capability set is high-risk and could directly facilitate unauthorized exploitation or data extraction if included in a larger package.

Confidence: 82%Severity: 86%
Audit Metadata
Analyzed At
Apr 6, 2026, 11:55 AM
Package URL
pkg:socket/skills-sh/mukul975%2Fanthropic-cybersecurity-skills%2Fexploiting-sql-injection-with-sqlmap%2F@d1e709243f9b7f0513d639127765efe4ff0482ad