Strix•sqlmap 用法 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Strix•sqlmap 用法 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Official docs:
Canonical syntax: sqlmap -u "<target_url_with_params>" [options]
High-signal flags:
-u, --url <url> target URL-r <request_file> raw HTTP request input-p <param> test specific parameter(s)--batch non-interactive mode--level <1-5> test depth--risk <1-3> payload risk profile--threads <n> concurrency--technique <letters> technique selection--forms parse and test forms from target page--cookie <cookie> and --headers <headers> authenticated context--timeout <seconds> and --retries <n> transport stability--tamper <scripts> WAF/input-filter evasion--random-agent randomize user-agent--ignore-proxy bypass configured proxy--dbs, -D <db> --tables, -D <db> -T <table> --columns, -D <db> -T <table> -C <cols> --dump--flush-session clear cached scan stateAgent-safe baseline for automation: sqlmap -u "https://target.tld/item?id=1" -p id --batch --level 2 --risk 1 --threads 5 --timeout 10 --retries 1 --random-agent
Common patterns:
sqlmap -u "https://target.tld/item?id=1" -p id --batch --level 2 --risk 1 --threads 5
sqlmap -u "https://target.tld/login" --data "user=admin&pass=test" -p pass --batch --level 2 --risk 1
sqlmap -u "https://target.tld/login" --forms --batch --level 2 --risk 1 --random-agent
sqlmap -u "https://target.tld/item?id=1" -p id --batch --dbs
sqlmap -u "https://target.tld/item?id=1" -p id --batch -D appdb --tables
sqlmap -u "https://target.tld/item?id=1" -p id --batch -D appdb -T users -C id,email,role --dump
Critical correctness rules:
--batch in automation to avoid interactive prompts.-p when possible.--flush-session when retesting after request/profile changes.--level 1-2, --risk 1) and escalate only when needed.Usage rules:
--cookie/--headers) aligned with manual validation state.-D/-T/-C) over broad dump-first behavior.-h/--help during normal execution unless absolutely necessary.Failure recovery:
--flush-session.--threads and test targeted --tamper chains.--level/--risk gradually.If uncertain, query web_search with: site:github.com/sqlmapproject/sqlmap/wiki/usage sqlmap <flag>
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.