sast-sqli

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is internally consistent with its stated purpose, but that purpose is to give an AI agent offensive security assessment capability focused on SQL injection. There is no clear credential theft, exfiltration, or suspicious install path, so this is not malware; however, it remains high risk because it operationalizes vulnerability discovery and suggested exploit verification.

Confidence: 88%Severity: 81%
Audit Metadata
Analyzed At
Apr 8, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/utkusen%2Fsast-skills%2Fsast-sqli%2F@bf141b73bd3a9630b08b350b044772e703a45733