Most alerts are false positives from Markdown fences, reserved example URLs, educational vulnerable code, and standard output paths. Confirmed issues include a remote script piped to Bash, a third-party action receiving a token, and commands for host file access and OS execution. Semantic review also found web-shell deployment, WAF evasion, and bulk credential extraction guidance that needs stronger controls.
The workflow pipes an unauthenticated download directly into Bash without a pinned version or checksum. A compromised source can execute arbitrary code in the CI runner.
The skill provides a SQLMap command that reads /etc/passwd from the target server. This is direct host file access and can expose system account information.
The skill instructs users to deploy shell.php into a web root and obtain operating-system or SQL shells. These actions enable arbitrary remote control.
The commands explicitly use file-write, os-shell, and sql-shell options against a target. The surrounding heading labels them as advanced exploitation.
The documented SQLMap command executes whoami on the target host. Remote operating-system command execution is a high-impact capability even in an authorized testing context.
The skill provides commands to dump entire databases, search password columns, extract administrator credentials, and enumerate database passwords and privileges.
The documented commands explicitly request dump-all, password columns, credential extraction, users, passwords, privileges, and all databases.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
The workflow passes GITHUB_TOKEN to gitleaks/gitleaks-action@v2, which is pinned only to a mutable tag. A compromised action could misuse the token despite the workflow's limited permissions.
Most template and reference-file detections are false positives because they are documentation, detection-rule examples, or CI reporting helpers. Confirmed risk remains high due to SQLMap guidance for data extraction, WAF evasion, file access, shell access, and a CI curl-to-shell installer.
The CI template downloads a remote install script and executes it through a shell pipeline. This creates a supply-chain execution risk without pinning or integrity verification.
The example explicitly reads /etc/passwd from a target through SQLMap. This is sensitive system password-file access and should be treated as a critical capability.
The advanced exploitation section shows target file reads, web-root file writes, operating-system command execution, and shell access.
The section includes /etc/passwd reading, shell.php file writing, os-cmd, os-shell, and sql-shell examples. These are direct post-exploitation capabilities.
The skill provides a full workflow for database dumping, password column extraction, admin credential extraction, and broad enumeration.
The cited sections explicitly describe dumping tables, searching password data, extracting admin credentials, and enumerating users and passwords. Authorization language is present, but the operational steps remain high-risk dual-use guidance.
The skill teaches tamper scripts, random user agents, delays, proxying, Tor, randomization, and method changes to bypass blocking.
Both cited sections explicitly frame the options as WAF bypass or responses to WAF blocking. These tactics can help evade defensive controls during unauthorized testing.
The example saves SQLMap session data to a SQLite file. Such output can contain sensitive target metadata or extracted results and needs retention controls.
Capability review items (67)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
The hardcoded URL is part of a remote installer that is piped to bash. This is risky because the CI job executes network-delivered code without verification.
The SQLMap example supports database dumping, credential extraction, or broad enumeration. Authorization warnings exist, but the capability can expose sensitive data.
The SQLMap example supports database dumping, credential extraction, or broad enumeration. Authorization warnings exist, but the capability can expose sensitive data.
The SQLMap example supports database dumping, credential extraction, or broad enumeration. Authorization warnings exist, but the capability can expose sensitive data.
The SQLMap example supports database dumping, credential extraction, or broad enumeration. Authorization warnings exist, but the capability can expose sensitive data.
The SQLMap example supports database dumping, credential extraction, or broad enumeration. Authorization warnings exist, but the capability can expose sensitive data.
The SQLMap example demonstrates command or SQL shell access after exploitation. This is high-risk post-exploitation guidance even with authorization caveats.
The SQLMap example demonstrates command or SQL shell access after exploitation. This is high-risk post-exploitation guidance even with authorization caveats.
The SQLMap example supports database dumping, credential extraction, or broad enumeration. Authorization warnings exist, but the capability can expose sensitive data.
The SQLMap example supports database dumping, credential extraction, or broad enumeration. Authorization warnings exist, but the capability can expose sensitive data.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
sqlmap -u "http://example.com/page?id=1&name=test" -p id
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command performs active SQL injection probing, fingerprinting, enumeration, or API testing. It can be legitimate when authorized, but it is still dual-use offensive tooling.
The SQLMap command is mainly about output, session, or traffic logging, but it still targets a web application with an offensive testing tool. The direct risk at this line is limited.
The SQLMap command is mainly about output, session, or traffic logging, but it still targets a web application with an offensive testing tool. The direct risk at this line is limited.
The SQLMap command is mainly about output, session, or traffic logging, but it still targets a web application with an offensive testing tool. The direct risk at this line is limited.
The SQLMap command is mainly about output, session, or traffic logging, but it still targets a web application with an offensive testing tool. The direct risk at this line is limited.
The SQLMap command is mainly about output, session, or traffic logging, but it still targets a web application with an offensive testing tool. The direct risk at this line is limited.
Most template and reference hits are documentation examples, placeholders, or Markdown artifacts and were marked false positive. Confirmed risks remain in the SQLMap guidance for data dumping, target file access, shell actions, evasion, and a CI template that pipes a remote script into bash. No prompt injection attempts were found in the reviewed files.
The CI template downloads a remote install script and pipes it directly to bash. That executes mutable network content without pinning or checksum verification.
The skill explicitly demonstrates using SQLMap to read /etc/passwd from a target server. That is invasive file access and can expose sensitive system information.
The line demonstrates SQLMap OS command execution against a target with whoami. This is a remote command execution impact test, not benign reconnaissance.
The placeholder URL appears in a SQLMap command for file access or shell creation against a target. The example teaches highly invasive exploitation behavior.
The placeholder URL appears in a SQLMap command for file access or shell creation against a target. The example teaches highly invasive exploitation behavior.
The placeholder URL appears in a SQLMap command for file access or shell creation against a target. The example teaches highly invasive exploitation behavior.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in a SQLMap command for data extraction, evasion, authentication bypass, or shell-style impact testing. This is dual-use offensive guidance.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
The placeholder URL appears in SQLMap enumeration or aggressive testing guidance. It is legitimate with authorization, but can expose target database metadata if misused.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
The static findings are mixed: generic reference templates create many false positives, but the main skill contains confirmed dual-use offensive sqlmap guidance. The skill is not deceptive and includes authorization warnings, but it provides explicit workflows for data extraction, file access, OS shells, WAF evasion, and Tor use, so it should not be published without strict marketplace controls.
5
Files scanned
1,984
Lines analyzed
10
Review items
2
False positives ignored
Capability review items (5)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
The main skill goes beyond detection and instructs users on database enumeration, table dumping, credential extraction, server file reads, file writes, and OS shell access. These are legitimate in authorized tests but can directly enable unauthorized compromise.
The cited sections explicitly describe data extraction, file access, and shell options in an sqlmap workflow. Authorization warnings reduce malicious-intent confidence but not operational risk.
The skill teaches tamper scripts, random user agents, proxy use, Tor checks, method changes, and randomized delays. These techniques can support authorized testing, but they also lower barriers for evasion during unauthorized attacks.
The cited sections are semantically about bypassing blocking controls and changing request behavior. Legitimate security testing is possible, but evasion content is clearly present.
Unsafe pipe-to-shell installer pattern in CI template
The CI template includes a curl-to-shell installation pattern. If copied into a workflow, this executes remote code from the network during CI and creates supply-chain risk.
The pattern is a real remote-code execution risk in CI templates. It appears educational rather than malicious, but the dangerous usage is concrete.
Many static external-command and network findings come from sqlmap command examples against example domains. The commands are not executed by the skill itself, but they are actionable instructions for invasive network testing.
The examples are documented commands rather than hidden code execution. Risk remains elevated because they are intended to be run by the user against web targets.
Credential and environment examples are mostly benign templates
The scanner flagged environment variables, token names, and secret examples in rule and CI templates. These are mostly demonstrative security-scanning examples, but they can normalize copying placeholder secrets or broad token access if used carelessly.
The semantic context is defensive examples and GitHub Actions configuration, so most secret hits are false positives. The confidence is medium because templates can still be copied into real workflows.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Static script and crypto hits in references are false positives
The document.write, innerHTML, MD5, SHA1, and API key patterns in the reference files are vulnerable-code examples used to teach detection and remediation. No evidence found that they are executable skill logic or hidden malicious behavior.
The surrounding text labels these snippets as examples, vulnerable patterns, and remediation material. This strongly supports a false-positive evaluation for those static hits.
No evidence found in the analyzed files for override instructions, fake system messages, pre-approval claims, or instructions to skip security review.
A targeted case-insensitive search across the listed files found no matching prompt-injection indicators. The confidence is high but limited to the inspected repository contents.
sqlmap table and credential dumpingsqlmap server file read and file writesqlmap OS shell and SQL shell optionsWAF bypass and Tor optionsRemote script execution in CI template
This skill wraps sqlmap, a legitimate open-source penetration testing tool. Static findings (273 patterns) are TRUE POSITIVES for security-relevant operations but represent intentional functionality for authorized security testing. The skill includes explicit authorization requirements and ethical use guidelines. SQL injection testing can be destructive to databases and requires strict authorization controls.
This skill wraps sqlmap, a legitimate open-source penetration testing tool. Static findings (273 patterns) are TRUE POSITIVES for security-relevant operations but represent intentional functionality for authorized security testing. The skill includes explicit authorization requirements and ethical use guidelines. SQL injection testing can be destructive to databases and requires strict authorization controls.
Pure documentation skill containing no executable code. Provides SQLMap usage guidance, workflow checklists, and CI/CD security templates. All content focuses on authorized penetration testing with explicit authorization requirements. No scripts, network calls, file system access, or command execution capabilities present.
5
Files scanned
1,059
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Pure documentation skill containing no executable code. Provides SQLMap usage guidance, workflow checklists, and CI/CD security templates. All content focuses on authorized penetration testing with explicit authorization requirements. No scripts, network calls, file system access, or command execution capabilities present.
5
Files scanned
1,059
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Pure documentation skill containing no executable code. Provides SQLMap usage guidance, workflow checklists, and CI/CD security templates. All content focuses on authorized penetration testing with explicit authorization requirements. No scripts, network calls, file system access, or command execution capabilities present.
5
Files scanned
1,059
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.