web-sqli

Warn

Audited by Socket on Sep 20, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an SQL injection exploitation playbook, but it is a high-risk offensive-security capability for an AI agent. No clear malicious installer or credential-harvesting infrastructure is present, yet the skill materially enables unauthorized exploitation, data extraction, file access, and command execution against external systems.

Confidence: 94%Severity: 89%
SecurityMEDIUM
cheatsheet.md

This is an offensive SQL injection testing cheat sheet, not malicious executable code. It contains high-impact exploitation guidance that could cause significant harm if applied without authorization, including credential extraction, file writes, command execution, and out-of-band exfiltration. Within the supplied file alone, there is no evidence of malware or autonomous malicious behavior.

Confidence: 99%Severity: 72%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-sqli%2F@bc9e2a3c1aa0f8a722c1f38e2da0d9a442f7815cf4a5ed2fb82f71cd7770eba4
Security Audit — socket — web-sqli