CtrlK
BlogDocsLog inGet started
Tessl Logo

sqlmap-database-pentesting

This skill should be used when the user asks to "automate SQL injection testing," "enumerate database structure," "extract database credentials using sqlmap," "dump tables and columns from a vulnerable database," or "perform automated database penetration testing." It provides comprehensive guidance for using SQLMap to detect and exploit SQL injection vulnerabilities.

64

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/sqlmap-database-pentesting/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable, executable sqlmap guidance with a well-sequenced core workflow, weakened by monolithic structure (no reference files despite ~400 lines of tables, examples, and troubleshooting) and the absence of validation checkpoints in a batch/destructive context, which caps workflow clarity. Minor redundancy between the per-stage Key Options, the Essential Options table, and the Quick Reference commands.

Suggestions

Add explicit validation checkpoints to the Core Workflow (e.g., 'confirm the injection is confirmed and database names are returned before proceeding to --tables', 'verify table list before dumping') so the batch/destructive cap on workflow clarity can lift.

Split the SKILL.md into one-level-deep reference files — e.g., references/troubleshooting.md for the issue/cause/solution section and references/techniques.md for the DBMS and injection-technique tables — leaving a lean overview with clearly signaled links.

Remove the duplicated option documentation: drop the per-stage 'Key Options' blocks and the 'Quick Reference Commands' table in favor of the single 'Essential Options' table.

DimensionReasoningScore

Conciseness

Command-dense with almost no explanation of concepts Claude already knows, but the per-stage 'Key Options' blocks duplicate the 'Essential Options' table (e.g., '--dbs: Enumerate database names' appears in both), and the 'Quick Reference Commands' table restates the workflow commands verbatim. Fits anchor 4 (efficient with trimmable redundancy) rather than 3 (no padded explanations) or 5 (real duplication exists).

4 / 5

Actionability

Fully executable copy-paste sqlmap commands throughout, a complete worked end-to-end example against testphp.vulnweb.com, and concrete troubleshooting flags (--tamper=space2comment, --time-sec=3, --start/--stop). Matches anchor 5 (copy-paste ready, common cases covered).

5 / 5

Workflow Clarity

The Core Workflow is well sequenced (manual verify -> --dbs -> --tables -> --columns -> --dump), but the rubric's cap applies: this involves batch and destructive operations (bulk '-m' scanning, '--dump-all', credential dumping) with no validation checkpoints inside the workflow, and the Troubleshooting section is reactive rather than in-flow validation. Capped at anchor 3, not 4, per the batch/destruction cap which takes precedence.

3 / 5

Progressive Disclosure

A monolithic single file with no reference files at all (no references/, scripts/, or assets/ exist), while the 13-row DBMS support table, the techniques table, and the Troubleshooting section are content that belongs in one-level-deep reference files. Section structure is decent and navigable, fitting anchor 3 (structure present but content that should be separate is inline) rather than 2 (headers and organization exist) or 4 (nothing is split out).

3 / 5

Total

15

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an exemplary explicit trigger clause and natural, tool-specific trigger phrases. Its main weakness is the generic 'provides comprehensive guidance' framing of the what, which pads rather than enumerates capabilities, and a few missing synonyms (SQLi, bare sqlmap).

DimensionReasoningScore

Specificity

Concrete actions are named ('enumerate database structure', 'dump tables and columns from a vulnerable database', 'detect and exploit SQL injection vulnerabilities'), but the capability statement itself leans on the padded phrase 'provides comprehensive guidance' rather than a crisp action list. This matches anchor 4 (several specific actions, minor gaps), not 3 (well beyond 1-2 actions) or 5 (the 'what' clause is less concrete than the trigger list).

4 / 5

Completeness

Both what and when are present: an explicit 'should be used when the user asks to...' clause plus a statement of what it provides. The 'when' is exemplary, but the 'what' ('provides comprehensive guidance for using SQLMap to detect and exploit SQL injection vulnerabilities') is generic, matching anchor 4 ('when' could be more specific / what is padded) rather than 5.

4 / 5

Trigger Term Quality

Quoted phrases like 'automate SQL injection testing', 'extract database credentials using sqlmap', and 'perform automated database penetration testing' are natural user requests. Missing common variations such as 'SQLi', 'sqli', or a bare 'sqlmap' trigger, so it fits anchor 4 (good coverage, a few natural terms missing) rather than 5.

4 / 5

Distinctiveness Conflict Risk

Clear niche (the SQLMap tool for SQL injection) with distinct, tool-specific trigger phrases; minimal conflict risk with any other skill. Matches anchor 5.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.