Skip to main content
sqli-sql-injectionby yaklang.io ProjectDevelopmentGitHub stars: 2.4k

SQL Injection skill: what it does and how to install it

Guides SQL injection testing across MySQL, MSSQL, Oracle and PostgreSQL, covering detection, blind inference, extraction and escalation paths.

Summary generated from the skill's documentation.

Install

$ npx skills add yaklang/hack-skills --skill sqli-sql-injection

Run it in a terminal. If your agent is already running, start a new session so it picks the skill up.

About this skill

What it does. Guides first-pass testing of SQL injection across URL, body, JSON, XML and header inputs, then routes through database fingerprinting, UNION extraction, boolean and time-based inference, out-of-band exfiltration, metadata discovery and OS command execution. It also covers second-order injection, parameterisation gaps and WAF evasion.

When to use it. When input may reach SQL queries in authentication, filtering, sorting, reporting or database-specific execution paths. Load its companion scenario and SQLMap references for specialised cases such as ORDER BY injection, GraphQL, framework bugs and advanced tamper techniques.

History

Repo stars

2.4k

Tracking since . A chart appears once there are 7 days of data.

Stars are counted for the whole repository, which holds 10 skills.

Installs

3.7k

Tracking since . A chart appears once there are 7 days of data.

Installs via skills.sh

Similar skills