sqlmap-database-pentesting

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents the use of SQLMap for database enumeration and exploitation, including high-risk operations on target servers such as executing OS commands (--os-cmd), obtaining an interactive shell (--os-shell), and performing file system actions (--file-read, --file-write).
  • [EXTERNAL_DOWNLOADS]: The instructions reference downloading the SQLMap utility from its public GitHub repository.
  • [PROMPT_INJECTION]: The skill defines a process that ingests and acts upon data from external web applications, which represents an indirect prompt injection surface.
  • Ingestion points: Data retrieved from target web applications during scanning and exploitation (SKILL.md).
  • Boundary markers: The provided methodology does not include explicit delimiters or instructions to ignore commands that may be embedded in the target data.
  • Capability inventory: The documented tool features powerful capabilities including remote command execution and file system access on the target (SKILL.md).
  • Sanitization: The skill does not detail any sanitization or validation of the tool's output before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 02:06 AM
Security Audit — agent-trust-hub — sqlmap-database-pentesting