webapp-sqlmap
Assess SQL Injection with SQLMap
Manual SQL injection testing is slow and inconsistent. This skill provides structured SQLMap commands, authorization checks, validation steps, and reporting guidance for approved assessments.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "webapp-sqlmap" from https://skillstore.io/skills/agentsecops-webapp-sqlmap.md and its manifest at https://skillstore.io/api/skills/agentsecops-webapp-sqlmap/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "webapp-sqlmap". Review an authorized staging endpoint with one numeric query parameter.
Expected outcome:
- Scope confirmed for the named staging host and parameter.
- Begin with low-risk detection and a single technique.
- Record response differences, request volume, and manual verification results.
Using "webapp-sqlmap". Plan testing for an authenticated JSON API during a maintenance window.
Expected outcome:
- Use the supplied request structure and approved authentication header.
- Apply the engagement rate limit and stop on instability.
- Request confirmation before enumerating database objects or extracting records.
Using "webapp-sqlmap". Turn a confirmed SQL injection result into a report.
Expected outcome:
- Summarize the affected endpoint, parameter, technique, and verified impact.
- Redact credentials and sampled records from shared evidence.
- Recommend parameterized queries, input validation, and least-privilege database access.
Security Audit
CriticalMost alerts are false positives from Markdown fences, reserved example URLs, educational vulnerable code, and standard output paths. Confirmed issues include a remote script piped to Bash, a third-party action receiving a token, and commands for host file access and OS execution. Semantic review also found web-shell deployment, WAF evasion, and bulk credential extraction guidance that needs stronger controls.
Confirmed security concerns (6)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (50)
๐ Network access (50)
๐ Filesystem access (4)
๐ Env variables (23)
โก Contains scripts (2)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/agentsecops-webapp-sqlmap/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/agentsecops-webapp-sqlmap?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/agentsecops-webapp-sqlmap?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/agentsecops-webapp-sqlmap/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/agentsecops-webapp-sqlmap.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
AgentSecOps. (2026). webapp-sqlmap security audit report (audit version 9) [Author version 0.1.0]. Skillstore. https://skillstore.io/skills/agentsecops-webapp-sqlmap/audits/9BibTeX citation
@techreport{agentsecops-agentsecops-webapp-sqlmap-2026,
author = {AgentSecOps},
title = {webapp-sqlmap security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/agentsecops-webapp-sqlmap/audits/9},
note = {Author version 0.1.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "webapp-sqlmap security audit report (audit version 9)"
version: "0.1.0"
type: report
authors:
- name: "AgentSecOps"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/agentsecops-webapp-sqlmap/audits/9"
identifiers:
- type: other
value: "skillstore:agentsecops-webapp-sqlmap:audit:9"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Validate a Staging Endpoint
Create a low-risk detection plan for an approved parameter and record reproducible evidence.
Add Controlled CI Testing
Define scoped SQL injection checks, rate limits, artifacts, and failure criteria for a test environment.
Confirm and Remediate a Finding
Verify a suspected injection flaw, classify impact, and produce defensive remediation guidance.
Try These Prompts
Within my written authorization for [target], prepare a minimal SQLMap detection plan for [parameter]. Start with low-risk checks and explain each option.
I have an authorized request file at [path]. Design a staged SQLMap workflow to identify the DBMS and enumerate only [approved objects].
Analyze this authorized API request: [request details]. Propose SQLMap options for JSON input, authentication headers, rate limits, and reliable false-positive checks.
For engagement [name], create a controlled SQLMap validation plan for [scope]. Require confirmation before extraction, file access, evasion, or command execution.
Best Practices
- Confirm written authorization, target scope, testing window, and data handling rules before any request.
- Start with low-risk detection, limit requests, and require approval before extraction or host interaction.
- Redact sensitive evidence, preserve an audit log, and verify every automated finding manually.
Avoid
- Do not test public, production, or third-party systems without explicit written permission.
- Do not begin with bulk dumping, file writes, shell access, WAF evasion, or maximum risk settings.
- Do not place real credentials, tokens, personal data, or complete database dumps in prompts or reports.
Frequently Asked Questions
Is written authorization required?
Does this skill install SQLMap?
Can it test production systems?
Which request types are supported?
Does it prevent destructive actions?
How should extracted data be handled?
Developer Details
Author
AgentSecOpsLicense
MIT
Author version
v0.1.0
Skillstore revision
r2
Ref
181fdefcafd96b041926e61c4b2e306ca7e7820e
Maintenance freshness
7/24/2026
Usage
9 downloads ยท 229 views
File structure