SQL Injection skill: what it does and how to install it
Guides SQL injection testing across MySQL, MSSQL, Oracle and PostgreSQL, covering detection, blind inference, extraction and escalation paths.
Summary generated from the skill's documentation.
Install
$ npx skills add yaklang/hack-skills --skill sqli-sql-injectionRun it in a terminal. If your agent is already running, start a new session so it picks the skill up.
About this skill
What it does. Guides first-pass testing of SQL injection across URL, body, JSON, XML and header inputs, then routes through database fingerprinting, UNION extraction, boolean and time-based inference, out-of-band exfiltration, metadata discovery and OS command execution. It also covers second-order injection, parameterisation gaps and WAF evasion.
When to use it. When input may reach SQL queries in authentication, filtering, sorting, reporting or database-specific execution paths. Load its companion scenario and SQLMap references for specialised cases such as ORDER BY injection, GraphQL, framework bugs and advanced tamper techniques.
History
Repo stars
2.4k
Tracking since . A chart appears once there are 7 days of data.
Stars are counted for the whole repository, which holds 10 skills.
Installs
3.7k
Tracking since . A chart appears once there are 7 days of data.
Installs via skills.sh
Similar skills
- Writing SkillsGuides creating, editing and testing skills before they are deployed.
- API and Interface DesignGuides the design of stable APIs and module boundaries, covering REST and GraphQL endpoints and type contracts between modules.
- YARA Rule AuthoringGuides the authoring of YARA-X detection rules for malware identification.