CtrlK
BlogDocsLog inGet started
Tessl Logo

sql-injection-testing

This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through injection", "detect SQL injection flaws", or "exploit database query vulnerabilities". It provides comprehensive techniques for identifying, exploiting, and understanding SQL injection attack vectors across different database systems.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/sql-injection-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and highly actionable as a payload reference, with a clear phased workflow and good troubleshooting coverage. Its two main weaknesses are token efficiency — most of the content is standard SQL injection knowledge Claude already has, duplicated across sections — and structure, since ~400 lines of payload catalogs live inline in SKILL.md instead of being split into referenced files.

Suggestions

Move the payload catalogs, Quick Reference tables, and worked Examples into references/payloads.md and references/examples.md, keeping SKILL.md as a concise overview of the four-phase workflow with one-level-deep, clearly signaled references.

Cut textbook material Claude already knows (UNION column counting, classic auth-bypass strings, basic sleep-based payloads) and keep only what adds value: scope/authorization gates, evidence-collection requirements, and report deliverable formats.

Either show concrete tool invocations (e.g. sqlmap command lines with the target parameter and session cookie) or drop SQLMap/Burp from the prerequisites, since they are currently named but never used.

DimensionReasoningScore

Conciseness

The ~440-line body is largely a textbook SQLi payload catalog — UNION column counting via ORDER BY, classic auth-bypass strings (' OR '1'='1), SLEEP-based blind extraction, comment-substitution filter evasion — all of which Claude already knows, which the guidelines explicitly penalize. It is noticeably verbose with several redundant sections (payload lists repeated in Quick Reference and Examples). Above 1 because it is structured reference material rather than padded prose explanation.

2 / 5

Actionability

Payloads are concrete and copy-paste ready, and the worked examples show full HTTP requests with expected responses ("GET /product.php?id=5 ORDER BY 4-- / Response: Normal"). Below 5 because named prerequisites (SQLMap, Burp Suite) never get a single invocation example — the tools are required but their use is left entirely to inference.

4 / 5

Workflow Clarity

A clear four-phase sequence (detection, exploitation, auth bypass, filter bypass) with embedded confirmations — true/false response comparison, ORDER BY-until-error column enumeration, delay confirmation — and a Troubleshooting section for error recovery. Below 5 because validation checkpoints are implicit inside phases rather than explicit gate steps, and the destructive-operation cap does not apply since destructive queries are explicitly forbidden in Constraints.

4 / 5

Progressive Disclosure

No bundle files exist at all: the entire skill is a monolithic SKILL.md where payload catalogs, quick-reference tables, and worked examples clearly belong in separate references/ files. Section headers are good, so above anchor 2 (no structure), but it matches anchor 3: content that should be separate is inlined with no one-level-deep references.

3 / 5

Total

13

/

20

Passed

Description

81%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with excellent, explicit trigger coverage (including the SQLi synonym) and a clearly distinct niche. The main weakness is the "what" half: it describes the skill only through generic verbs and the buzzword "comprehensive techniques" instead of naming concrete capabilities like authentication bypass, schema extraction, or blind injection testing.

Suggestions

Replace 'provides comprehensive techniques' with concrete capabilities, e.g. 'Runs detection payloads, bypasses login forms, extracts database schemas, and performs blind/time-based injection testing across MySQL, MSSQL, PostgreSQL, and Oracle.'

Drop the filler word 'comprehensive' and 'understanding' (an internal state, not a deliverable) to tighten the what-statement.

DimensionReasoningScore

Specificity

The description names the domain and verbs ("identifying, exploiting, and understanding SQL injection attack vectors") but the actions are generic and rest on the buzzword "comprehensive techniques"; no concrete capabilities (schema extraction, login bypass, payload testing) are stated. This matches the anchor 'names domain and 1-2 concrete actions, but not comprehensive' — below 4 which requires several specific actions, above 2 because real actions are named.

3 / 5

Completeness

Both halves are explicit: an explicit trigger clause ("This skill should be used when the user asks to...") with concrete quoted phrases, and a stated "what" ("provides comprehensive techniques for identifying, exploiting, and understanding SQL injection attack vectors across different database systems"). Below 5 because the "what" leans on the vague "comprehensive techniques" rather than concrete capabilities; above 3 because the "when" is explicit, not merely implied.

4 / 5

Trigger Term Quality

Six natural quoted trigger phrases cover the space well, including the abbreviation synonym "perform SQLi attacks" plus test/detect/extract/bypass/exploit variations ("test for SQL injection vulnerabilities", "detect SQL injection flaws", "bypass authentication using SQL injection"). This is comprehensive natural-term coverage with synonyms, matching the top anchor.

5 / 5

Distinctiveness Conflict Risk

SQL injection testing is a clear niche with distinct, specific trigger phrases ("test for SQL injection vulnerabilities", "perform SQLi attacks") that no other skill category would claim. Voice is third person ("This skill should be used"), so no penalty applies. Minimal conflict risk matches the top anchor.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.