pytm
81Build pytm Threat Models as Code
Threat modeling often becomes outdated and disconnected from architecture changes. This skill helps create pytm models, STRIDE analysis, and diagram workflows for security reviews and CI.
Assess SQL Injection with SQLMap
Manual SQL injection testing is slow and inconsistent. This skill provides structured SQLMap commands, authorization checks, validation steps, and reporting guidance for approved assessments.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "webapp-sqlmap" from https://skillstore.io/skills/agentsecops-webapp-sqlmap.md and its manifest at https://skillstore.io/api/skills/agentsecops-webapp-sqlmap/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "webapp-sqlmap". Review an authorized staging endpoint with one numeric query parameter.
Expected outcome:
Using "webapp-sqlmap". Plan testing for an authenticated JSON API during a maintenance window.
Expected outcome:
Using "webapp-sqlmap". Turn a confirmed SQL injection result into a report.
Expected outcome:
Most alerts are false positives from Markdown fences, reserved example URLs, educational vulnerable code, and standard output paths. Confirmed issues include a remote script piped to Bash, a third-party action receiving a token, and commands for host file access and OS execution. Semantic review also found web-shell deployment, WAF evasion, and bulk credential extraction guidance that needs stronger controls.
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/agentsecops-webapp-sqlmap/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/agentsecops-webapp-sqlmap?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/agentsecops-webapp-sqlmap?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/agentsecops-webapp-sqlmap/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/agentsecops-webapp-sqlmap.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>AgentSecOps. (2026). webapp-sqlmap security audit report (audit version 9) [Author version 0.1.0]. Skillstore. https://skillstore.io/skills/agentsecops-webapp-sqlmap/audits/9@techreport{agentsecops-agentsecops-webapp-sqlmap-2026,
author = {AgentSecOps},
title = {webapp-sqlmap security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/agentsecops-webapp-sqlmap/audits/9},
note = {Author version 0.1.0}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "webapp-sqlmap security audit report (audit version 9)"
version: "0.1.0"
type: report
authors:
- name: "AgentSecOps"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/agentsecops-webapp-sqlmap/audits/9"
identifiers:
- type: other
value: "skillstore:agentsecops-webapp-sqlmap:audit:9"
description: "Skillstore immutable audit report identifier"
Create a low-risk detection plan for an approved parameter and record reproducible evidence.
Define scoped SQL injection checks, rate limits, artifacts, and failure criteria for a test environment.
Verify a suspected injection flaw, classify impact, and produce defensive remediation guidance.
Within my written authorization for [target], prepare a minimal SQLMap detection plan for [parameter]. Start with low-risk checks and explain each option.
I have an authorized request file at [path]. Design a staged SQLMap workflow to identify the DBMS and enumerate only [approved objects].
Analyze this authorized API request: [request details]. Propose SQLMap options for JSON input, authentication headers, rate limits, and reliable false-positive checks.
For engagement [name], create a controlled SQLMap validation plan for [scope]. Require confirmation before extraction, file access, evasion, or command execution.
Author
AgentSecOpsLicense
MIT
Author version
v0.1.0
Skillstore revision
r2
Ref
181fdefcafd96b041926e61c4b2e306ca7e7820e
Maintenance freshness
7/24/2026
Usage
9 downloads ยท 229 views
File structure
Build pytm Threat Models as Code
Threat modeling often becomes outdated and disconnected from architecture changes. This skill helps create pytm models, STRIDE analysis, and diagram workflows for security reviews and CI.
Secure Dockerfiles with Hadolint
Dockerfile mistakes can create insecure and unreliable container images. This skill provides Hadolint workflows, rule guidance, remediation examples, and reusable CI configurations.
Run Authorized Nuclei Security Scans
Known vulnerabilities and misconfigurations can escape manual review. This skill guides authorized Nuclei scans, template selection, validation, and reporting.
Audit Code with Semgrep
Security flaws can remain hidden across large, multilingual repositories. This skill guides focused Semgrep scans, triage, custom rules, CI gates, and standards-aligned remediation.
Scan Dependencies and Containers with Trivy
Security teams need consistent visibility into vulnerable components, images, and infrastructure configuration. This skill provides practical Trivy workflows for assessment, reporting, and remediation.
Automate OWASP ZAP DAST Scans
Security teams need repeatable runtime testing before releases. This skill guides authorized OWASP ZAP scans, authentication setup, API testing, and CI reporting.
Audit SQL Injection With sqlmap
by sickn33
SQL injection testing requires careful scope, repeatable checks, and clear reporting. This skill gives authorized testers a structured sqlmap workflow from detection through evidence review.
Assess SQL Injection with SQLMap
by sickn33
SQL injection testing needs repeatable checks and strict scope control. This skill guides authorized SQLMap workflows for discovery, enumeration, and reporting.
Test SQL Injection Safely
by sickn33
SQL injection testing needs clear scope and careful evidence handling. This skill helps authorized teams plan checks, understand techniques, and report fixes.
Run OWASP Web Security Testing
by sickn33
Web teams need a repeatable way to check common application risks before release. This skill organizes OWASP testing into phases, prompts, and reporting steps.
Assess IDOR Authorization Controls
by sickn33
Object references can expose or modify another user's resources when authorization checks fail. This skill structures authorized testing, evidence collection, impact analysis, and remediation.
Assess Security Scanning Workflows
by sickn33
Security teams need consistent methods for authorized vulnerability scans and assessment reports. This skill organizes common tools, workflows, outputs, and reporting steps for controlled security reviews.