sql-injection-testing
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
- [DATA_EXFILTRATION]: The skill provides instructions and specific payloads for Out-of-Band (OOB) data extraction. These payloads are designed to exfiltrate database information to external, non-whitelisted domains such as 'attacker.com' and 'attacker-server.com' through DNS and HTTP requests.
- [EXTERNAL_DOWNLOADS]: The documentation identifies requirements for third-party security software, specifically Burp Suite and SQLMap, which must be obtained and installed by the user or agent environment.
- [PROMPT_INJECTION]: The skill describes a workflow that ingests untrusted data from target web applications, creating an indirect prompt injection surface.
- Ingestion points: User-controlled target URLs and the subsequent HTTP responses from those applications (SKILL.md).
- Boundary markers: Absent. The skill does not provide specific delimiters or instructions to ignore potential commands embedded in application responses.
- Capability inventory: The agent is instructed to craft and send HTTP requests containing arbitrary SQL payloads based on the information gathered.
- Sanitization: Absent. There are no instructions for validating or escaping content received from the target application before it is processed by the agent.
- [NO_CODE]: This skill consists entirely of instructional markdown and documentation; it does not contain any executable scripts, binaries, or automated code functions.
Audit Metadata