sql-injection-testing

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides an extensive repository of SQL payloads for systematic vulnerability testing, including boolean-based, UNION-based, and time-based injection techniques targeting MySQL, MSSQL, PostgreSQL, and Oracle databases.\n- [DATA_EXFILTRATION]: Documents out-of-band (OOB) exfiltration techniques using DNS and HTTP requests to external domains (e.g., attacker.com, attacker-server.com). These are presented as instructional examples for demonstrating how data can be leaked from a vulnerable database.\n- [OBFUSCATION]: Includes instructions for evading security filters using various techniques such as URL encoding (%27), hexadecimal strings (0x61646D696E), whitespace substitution with comments (/**/), and keyword manipulation (SeLeCt, SEL/*bypass*/ECT).\n- [INDIRECT_PROMPT_INJECTION]:\n
  • Ingestion points: Interacts with user-provided target URLs and analyzes subsequent HTTP responses from remote web applications.\n
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within the remote responses are provided.\n
  • Capability inventory: Employs external security tools (SQLMap, Burp Suite) and executes manual SQL queries against target endpoints.\n
  • Sanitization: The skill lacks explicit instructions for sanitizing or validating the content returned by the target application, though the workflow focuses on observing structural changes (errors, delays, response length) rather than executing instructions from the response body.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:32 PM
Security Audit — agent-trust-hub — sql-injection-testing