sql-injection-testing
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill provides templates for SQL injection payloads designed to exfiltrate database contents via out-of-band channels (DNS and HTTP) to external domains such as
attacker.comandattacker-server.com.- [COMMAND_EXECUTION]: The technical requirements specify the use of automated tools such as SQLMap, which are used to execute queries against target systems.- [PROMPT_INJECTION]: The skill implements a 'Mandatory confirmation gate' requiring users to confirm authorization, target scope, and command effects, reducing the risk of accidental or malicious automated use.
Audit Metadata