sqlmap-database-pentesting
Warn
Audited by Socket on Jun 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent, but its purpose is to equip an AI agent with offensive penetration-testing and exploitation capabilities: SQL injection automation, credential/data extraction, remote command execution, and file upload. Install provenance for `sqlmap` is mostly legitimate, so this is not confirmed malware, but it is a high-risk security skill that should not be enabled for general-purpose agents without strict human oversight and scope controls.
Confidence: 95%Severity: 93%
Audit Metadata