AgentReadyHomeAgent ListingRuntimePricing

← Agent Listing

offensive-sqli (Claude-Red)

Agent SkillsFreeOpen Source

SQL injection testing skill: error/UNION/blind/OOB/second-order/NoSQL/GraphQL with WAF bypass and SQLmap.

🛡️ AgentReady threat assessment

MAESTRO 7-layer threat model + OWASP AIVSS risk score for offensive-sqli (Claude-Red), derived from its capabilities.

AIVSS 9.4 · Critical
View MAESTRO 7-layer threat model →

These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.

Overview

An offensive-security skill from the Claude-Red library covering the full SQLi surface — error-based, UNION, boolean/time blind, out-of-band, second-order, NoSQL, GraphQL, WebSocket, and JSON-operator injection — plus WAF bypass, DB-specific exploitation (MySQL/MSSQL/PostgreSQL/Oracle), and SQLmap automation. Surface: guides injection payload crafting and drives SQLmap against targets.

Key features and capabilities

Use cases