Hunt Sqli
Description
--- description: Active SQL injection hunt for an ingested program. Consumes webvuln-surface seeds + optional auth-context, tests each injection point via Burp using error-based, boolean-blind, time-blind, and UNION detection. Confirms to the proof ceiling (boolean-diff / time-delay / version read — never dump tables, never write). Writes redacted candidates; does not verify ownership or draft. argument-hint: <program-slug> allowed-tools: Agent --- You are kicking off active SQL injection hunti
Installation
Installs to ~/.claude/commands/kennyalfredo-pr-agent-hunt-sqli.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/Kennyalfredo/pr-agent/HEAD/.claude/commands/hunt-sqli.md -o ~/.claude/commands/kennyalfredo-pr-agent-hunt-sqli.md Restart Claude Code, or start a new session, for it to be picked up.
Full documentation available on GitHub
View Source RepositoryRelated Skills
mcp-server-postgres
Read-only PostgreSQL database access.
Data mcp-server-sqlite
SQLite database interaction and querying.
Data mcp-server-google-maps
Google Maps integration for location data.
Data Bitbucket Data Center
---
Data Private Gpt
Complete API layer for private AI applications on local models: RAG, skills, tools, MCP, text-to-sql, and more
Data Csv Data Summarizer
Automatically analyze CSV files and generate comprehensive insights with visualizations
Data