web-sqli
Audited by Socket on Sep 20, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill is internally coherent as an SQL injection exploitation playbook, but it is a high-risk offensive-security capability for an AI agent. No clear malicious installer or credential-harvesting infrastructure is present, yet the skill materially enables unauthorized exploitation, data extraction, file access, and command execution against external systems.
This is an offensive SQL injection testing cheat sheet, not malicious executable code. It contains high-impact exploitation guidance that could cause significant harm if applied without authorization, including credential extraction, file writes, command execution, and out-of-band exfiltration. Within the supplied file alone, there is no evidence of malware or autonomous malicious behavior.