mysql-pentesting
Audited by Socket on Aug 12, 2026
2 alerts found:
SecurityMalware该 Skill 的能力与其“mysql-pentesting”名称一致,但其用途本身是为 AI Agent 提供完整的数据库攻击与主机提权路径,包括凭据窃取、文件外带、RCE 与持久化。未见明显伪装或隐蔽恶意,但作为可执行的攻击性技能,整体应归为高风险、可疑而非确认恶意。
The provided fragment is explicit offensive exploitation guidance for MySQL/MariaDB and JDBC clients, demonstrating multiple high-impact compromise paths: arbitrary file read/write, UDF-based native code execution leading to OS command execution (including reverse shells), persistence via webshell/cron/SSH key writes, and potential JDBC RCE/local file exfiltration via attacker-controlled connection parameters and rogue-server flows. There is no indication of legitimate functionality; it should be treated as malicious weaponization material rather than safe dependency code.