sqli-sql-injection

Fail

Audited by Socket on Jul 21, 2026

3 alerts found:

SecurityMalwarex2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: install trust is relatively low concern, but the skill’s actual purpose is to give an AI agent offensive SQL exploitation, exfiltration, and OS-compromise techniques. Its footprint is coherent with that offensive purpose, yet the capability itself is high-risk and inappropriate for general agent deployment.

Confidence: 95%Severity: 93%
MalwareHIGH
SCENARIOS.md

This fragment is overwhelmingly malicious in intent: it is an offensive exploitation payload collection for multiple database engines, including explicit escalation pathways to command execution and persistence (IBM i command execution; SQLite webshell/cron-style drops; SQLite native code loading). It also includes WAF/filter-evasion techniques and blind extraction templates for data theft. If embedded in a dependency, it would represent a critical supply-chain security concern. Limited context is provided, so certainty about actual execution within a package cannot be fully established, but the indicators of malicious capability are very strong.

Confidence: 86%Severity: 97%
MalwareHIGH
SQLMAP_ADVANCED.md

This fragment is not a legitimate dependency implementation; it is an actionable offensive exploitation cheat sheet for GraphQL/SQL injection with WAF bypass techniques and database-specific primitives enabling high-impact outcomes (OS command execution, file/webshell writes, and external callback/exfiltration). Its presence in a software supply chain would be a critical malicious-content red flag rather than benign documentation.

Confidence: 86%Severity: 98%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fsqli-sql-injection%2F@c6366d440bd7bb81efacfd4e7307c0368e93c34da1e25edff07cb37a85cc3a31
Security Audit — socket — sqli-sql-injection