sqli-sql-injection
Audited by Socket on Jul 21, 2026
3 alerts found:
SecurityMalwarex2SUSPICIOUS: install trust is relatively low concern, but the skill’s actual purpose is to give an AI agent offensive SQL exploitation, exfiltration, and OS-compromise techniques. Its footprint is coherent with that offensive purpose, yet the capability itself is high-risk and inappropriate for general agent deployment.
This fragment is overwhelmingly malicious in intent: it is an offensive exploitation payload collection for multiple database engines, including explicit escalation pathways to command execution and persistence (IBM i command execution; SQLite webshell/cron-style drops; SQLite native code loading). It also includes WAF/filter-evasion techniques and blind extraction templates for data theft. If embedded in a dependency, it would represent a critical supply-chain security concern. Limited context is provided, so certainty about actual execution within a package cannot be fully established, but the indicators of malicious capability are very strong.
This fragment is not a legitimate dependency implementation; it is an actionable offensive exploitation cheat sheet for GraphQL/SQL injection with WAF bypass techniques and database-specific primitives enabling high-impact outcomes (OS command execution, file/webshell writes, and external callback/exfiltration). Its presence in a software supply chain would be a critical malicious-content red flag rather than benign documentation.