SQL Injection Testing

Warn

Audited by Socket on Feb 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Generic secret pattern detected All findings: [HIGH] hardcoded_secrets: Generic secret pattern detected (HS005) [AITech 8.2] [HIGH] hardcoded_secrets: Generic secret pattern detected (HS005) [AITech 8.2] This skill is a comprehensive offensive SQL injection playbook intended for penetration testers. Its capabilities align with its stated purpose, and references to standard tools are legitimate. However, it contains many direct, copy-pasteable payloads for authentication bypass, data extraction, and out-of-band exfiltration to arbitrary external domains. While not code-executing malware itself, the document is high-risk due to dual-use: it can be readily abused by unauthorized actors. Use is acceptable only within strict legal authorization and controlled testing environments; distribution in public repositories without access controls or ethical constraints is dangerous. LLM verification: This document is a high-risk, dual-use offensive testing guide: it contains explicit, actionable SQL injection exploitation recipes including authentication bypass and out-of-band exfiltration techniques. While legitimate for authorized security testing, in an uncontrolled environment it materially increases risk of data theft and unauthorized access. No embedded secrets or obfuscation were found, but the concrete OOB exfiltration examples (attacker domains, SMB/DNS/HTTP callbacks) are the most

Confidence: 80%Severity: 85%
Audit Metadata
Analyzed At
Feb 19, 2026, 06:41 PM
Package URL
pkg:socket/skills-sh/jpropato%2Fsiba%2Fsql-injection-testing%2F@f865621f4c657609ce1ecee1a578fda15db333ce