在授权渗透测试中挖掘 SQL/NoSQL 注入(SQLi、NoSQLi,含 WAF 绕过、盲注、堆叠查询、类型混淆注入)。当用户输入拼进 SQL/NoSQL 查询时使用——典型场景:id/搜索/排序/过滤参数、数组键当 SQL 片段、PHP 类型混淆、MongoDB `$where`/`$regex`、堆叠查询到 xp_cmdshell。适用目标类型 Web / REST API。触发场景包括用户说"测下 SQL 注入""这个参数能不能注入""盲注/时间注入试试""NoSQL/MongoDB 注入看一下"。输出:注入点 + 类型 + 证据的 finding(含 killed 记录)。
日本語の概要は準備中です。原文の説明を表示しています。
galact-byte/galact-Skills☆ 72026年10月2日 更新
Supabase (オープンソース Firebase 代替・BaaS) リファレンス。 PostgreSQL データベース、Auth (Email / OAuth / Magic Link / Phone / SSO)、Storage、 Edge Functions (Deno)、Realtime (subscriptions / presence / broadcast)、Vector embeddings、 supabase-js、supabase CLI、RLS (Row Level Security)、migrations。 PostgreSQL ベース。SQL Server / node-mssql は別スキル mssql。
Fandhe-AI/agent-reference-skills☆ 42026年10月9日 更新
Drizzle ORM (TypeScript ORM, drizzle-orm / drizzle-kit) の API リファレンス。 pgTable / mysqlTable / sqliteTable, `drizzle()`, `$inferSelect` / `$inferInsert`, RQB (Relational Queries) / `db.query`, `defineRelations`, magic `sql` operator, `drizzle-kit generate` / `push`, `drizzle.config.ts`, drizzle-zod, drizzle-seed, Drizzle Studio。SQL Server の低レベルドライバーは別スキル mssql。
Fandhe-AI/agent-reference-skills☆ 42026年10月9日 更新
Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution. Activates for requests involving SQL injection testing, SQLi exploitation, database security assessment, or injection vulnerability verification.
日本語の概要は準備中です。原文の説明を表示しています。
aniket2348823/Vul-Agent☆ 22026年6月9日 更新
Hunting skill for sqli vulnerabilities. Built from 12 public bug bounty reports including modern NoSQL injection (Rocket.Chat CVE-2021-22911 MongoDB $regex, Mongoose ORM CVE-2024-53900 $where bypass), modern ORM raw-fragment SQLi (Django CVE-2024-42005, Sequelize GHSA-wrh9-cjv3-2hpw), second-order SOQL injection (HackerOne Salesforce), time-based blind SQLi in GraphQL resolvers, and SQLi on OIDC-proxy backends. Use when hunting SQLi on any target. Dedicated NoSQL operator injection (MongoDB/CouchDB $where/$regex/$ne) is owned by hunt-nosqli — NoSQL appears here only as adjacent ORM/WAF context.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
SQL injection testing skill for offensive security assessments and bug bounty hunting. Covers error-based, UNION-based, boolean/time-based blind, out-of-band, second-order, NoSQL, GraphQL, WebSocket, and JSON-operator SQLi. Includes WAF bypass techniques, database-specific exploitation (MySQL, MSSQL, PostgreSQL, Oracle), cloud-native attack paths, ORM CVE tracking, and SQLmap automation. Use when performing web application SQL injection testing, database enumeration, privilege escalation via SQLi, or assessing injection vectors in APIs and modern stacks.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Advises on Amazon RDS open-source engines (MySQL, MariaDB, PostgreSQL) for instance creation, upgrade planning, commitment pricing, proxy evaluation, and Blue/Green deployments. Handles any RDS MySQL, MariaDB, or PostgreSQL question, including create a production-ready RDS MySQL instance, provision an RDS PostgreSQL database, run the RDS upgrade advisor for my RDS MySQL instance, what are my upgrade options, upgrade RDS MariaDB from 10.6 to the latest version, should I buy reserved instances or a savings plan for db.r7g.2xlarge RDS MySQL, change a VARCHAR to INT column on RDS MySQL 8.0 with Blue/Green, and does RDS Proxy help when PgBouncer already runs in transaction mode. Covers instance creation with production best practices, describe-db-instances and describe-db-engine-versions upgrade-target workflow, live prechecks via SSM or direct connection, RI versus DSP commitment pricing, RDS Proxy versus PgBouncer, and Blue/Green lifecycle with binlog replay compatibility.
日本語の概要は準備中です。原文の説明を表示しています。
aws/agent-toolkit-for-aws☆ 2,8432026年10月10日 更新
Expert knowledge for Azure Database Migration Service development including troubleshooting, decision making, limits & quotas, security, integrations & coding patterns, and deployment. Use when planning Azure DMS migrations for MySQL, PostgreSQL, MongoDB, SSIS-to-Azure SQL, or hybrid workloads, and other Azure Database Migration Service related development tasks. Not for Azure Migrate (use azure-migrate), Azure SQL Database (use azure-sql-database), Azure SQL Managed Instance (use azure-sql-managed-instance), SQL Server on Azure Virtual Machines (use azure-sql-virtual-machines).
日本語の概要は準備中です。原文の説明を表示しています。
MicrosoftDocs/Agent-Skills☆ 7772026年10月11日 更新
Use when the user wants to run SQL - especially analytical SQL - on local files (parquet/csv/json), URLs, S3 paths, or remote databases (Postgres, MySQL, MongoDB, ClickHouse Cloud, Iceberg, Delta Lake) without setting up a server. Provides chDB - embedded ClickHouse SQL in Python with 1000+ functions, Session for stateful multi-step pipelines, parametrized queries, and cross-source joins via `s3()`, `mysql()`, `postgresql()`, `iceberg()`, `deltaLake()`, `remoteSecure()` table functions. TRIGGER when: user wants SQL on parquet/csv/files or across remote analytical sources; uses ClickHouse SQL features (window functions, windowFunnel, geoToH3, JSON path ops, Session, parametrized queries); imports `chdb` or calls `chdb.query()`. SKIP this skill for pandas-style DataFrame method-chaining (use chdb-datastore instead) or ClickHouse server administration.
日本語の概要は準備中です。原文の説明を表示しています。
cline/plugins☆ 352026年9月19日 更新
Detect and exploit SQL injection vulnerabilities using both manual techniques and automated tools. Use this skill when testing web applications for database injection flaws including UNION-based, error-based, blind boolean, blind time-based, and out-of-band SQL injection. Covers WAF bypass, second-order SQLi, authentication bypass, and full database extraction with sqlmap.
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
Create a MySQL CDC capture using flowctl with binlog replication. Use when setting up streaming from MySQL, Amazon RDS MySQL, or Aurora MySQL. Use when user says "capture MySQL", "stream from MySQL", "MySQL CDC", "binlog replication", or "connect MySQL to Estuary".
日本語の概要は準備中です。原文の説明を表示しています。
estuary/agent-skills☆ 72026年9月25日 更新
Amazon Aurora PostgreSQL — creates, modifies, and advises on Aurora PostgreSQL clusters specifically (PostgreSQL-compatible engine, Aurora serverless, express configuration, pgvector, Babelfish). Trigger for Aurora PostgreSQL cluster operations, express-configuration quick-start, ACU sizing, I/O-Optimized storage, commitment pricing, or PostgreSQL upgrade planning. For Aurora MySQL, use amazon-aurora-mysql instead. Contains safety guardrails, express-first routing, and response templates that override defaults.
日本語の概要は準備中です。原文の説明を表示しています。
aws/agent-toolkit-for-aws☆ 2,8432026年10月10日 更新
SQL database migrations with zero-downtime strategies for PostgreSQL, MySQL, SQL Server
日本語の概要は準備中です。原文の説明を表示しています。
rmyndharis/antigravity-skills☆ 1,7302026年10月1日 更新
Manages a Fabric SQL database item, the OLTP SQL Server engine, including running T-SQL through sqlcmd, temporal and vector similarity search, schema and sys.tables inspection, dacpac deployment, and Query Store, blocked sessions and regressed-plan investigation. Use for any query or change against a SQL database item. Warehouse, lakehouse SQL endpoint and mirrored items belong to sqldw-cli.
日本語の概要は準備中です。原文の説明を表示しています。
microsoft/skills-for-fabric☆ 1,2422026年10月5日 更新
Expert knowledge for SQL Server on Azure Virtual Machines development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when planning SQL VM vs Managed Instance, Always On/FCI HADR, DTU/capacity limits, Key Vault/MI security, or Blob backups, and other SQL Server on Azure Virtual Machines related development tasks. Not for Azure SQL Database (use azure-sql-database), Azure SQL Managed Instance (use azure-sql-managed-instance), Azure Virtual Machines (use azure-virtual-machines), Azure Data Science Virtual Machines (use azure-data-science-vm).
日本語の概要は準備中です。原文の説明を表示しています。
MicrosoftDocs/Agent-Skills☆ 7772026年10月11日 更新
SQL injection occurs when untrusted user input is interpolated directly into database queries, allowing attackers to alter query logic. Detect via single-quote errors, boolean-based blind responses (AND 1=1 vs AND 1=2), time-delay payloads (SLEEP, WAITFOR), UNION column enumeration, and error messages from MySQL, Oracle, MSSQL, PostgreSQL. Tools: sqlmap, sqlbftools, Burp Suite, wfuzz with SQLi fuzz strings.
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
使用 AACT (Aggregate Analysis of ClinicalTrials.gov) PostgreSQL 数据仓库进行批量、历史、聚合性临床试验数据挖掘。Use this skill when the user requests bulk SQL analysis over the full clinical trials data warehouse — historical trial trends, disease landscapes, similar-design matching, or multi-year aggregations across hundreds of thousands of NCT records. 触发场景包括:AACT 查询、临床试验批量分析、PostgreSQL 试验数据、全量 NCT 检索、试验数据挖掘、历史试验分析、clinical trials data warehouse、SQL trials、bulk trial analysis、disease landscape、试验设计相似性匹配、跨年度聚合、sponsor/phase/country 多维统计。**与 clinical-trials-v2 差异**:本 skill 走批量 SQL · 离线大数据(PostgreSQL);v2 走实时 API · 单查询。两者互补:单条 NCT 实时状态用 v2,百万级历史挖掘用本 skill。支持云端公共 PostgreSQL(aact-db.ctti-clinicaltrials.org · 零部署)和每日 dump 本地还原(高性能 · 离线)两种连接方式,自动检测优先用本地。跨平台(macOS/Linux/Windows)参数化 SQL 防注入,read-only 强制保护。
日本語の概要は準備中です。原文の説明を表示しています。
EthanYoQ/Skill-hub☆ 112026年10月5日 更新
Next.js + Better Auth + PostgreSQL を Docker で構築し、Cloud Run へデプロイするスキル。ローカル開発環境のセットアップから Docker Compose、Dockerfile 作成、Cloud Run + Cloud SQL + Secret Manager を使った本番デプロイまでをカバーする。「Next.js と Better Auth でアプリを作りたい」「Docker で PostgreSQL を使いたい」「Docker で構築したい」「Docker Compose を使いたい」「アプリを Docker 化したい」「Dockerfile を書きたい」「Cloud Run にデプロイしたい」「Cloud SQL や Secret Manager を使いたい」ときに使う。
hukusuke1007/agent-skills☆ 82026年9月12日 更新
Specialized skill for containerized database testing using Testcontainers. Use when testing real database behavior, using SQL Server/PostgreSQL/MySQL containers, testing EF Core/Dapper. Covers container startup, database migrations, test isolation, container sharing. Keywords: testcontainers, container testing, database testing, MsSqlContainer, PostgreSqlContainer, MySqlContainer, EF Core testing, Dapper testing, Testcontainers.MsSql, Testcontainers.PostgreSql, GetConnectionString, IAsyncLifetime, CollectionFixture
日本語の概要は準備中です。原文の説明を表示しています。
rudironsoni/Synaxis☆ 22026年3月17日 更新
Notionのローカル保存データを検索し、ページやデータベースの一覧・件数・同期状況を確認して、必要に応じてMarkdownを書き出すスキル。
- 保存済みのNotionページを探したいとき
- データベース一覧やレポートを確認したいとき
- SQLで保存済みページの件数を数えたいとき
openclaw/openclaw☆ 39.2万2026年10月11日 更新
Granolaのローカルアーカイブから会議メモや文字起こしを検索・取得するスキル。同期状態を確認し、必要な更新やSQLによる正確な件数集計も扱います。
- 話題から過去の会議メモを探したいとき
- メモの文字起こしやパネルの取得
- 最近の情報を調べる前の同期状態確認
openclaw/openclaw☆ 39.2万2026年10月11日 更新
Perlコードの入力処理、ファイル操作、外部コマンド、SQL、Web出力を点検し、具体例とチェックリストに沿って安全な実装へ見直すスキル。
- Perlの入力検証を点検したいとき
- ファイル操作とコマンド実行の確認
- DBIのSQLインジェクション対策
affaan-m/ECC☆ 27.7万2026年10月10日 更新
プロンプト、正規表現、SQL、小さなコードを、採点基準に沿って繰り返し改良します。AIが候補を作り、失敗例を手がかりによりよい案を探すスキルです。
- 正解例に沿ってプロンプトを改善したいとき
- 合格率で正規表現を調整したいとき
- テストでSQLやコードを改善したいとき
NousResearch/hermes-agent☆ 25.3万2026年10月11日 更新
Manage Fabric Warehouse, Lakehouse SQL endpoints, and Mirrored Databases: DDL/DML, COPY INTO, read-only T-SQL, Query Insights diagnostics, and Capacity Metrics CU-spike correlation. Synapse migration target SQL belongs to synapse-migration; Fabric SQL database belongs to sqldb-cli. Triggers: query warehouse, create warehouse table, failed or canceled query, CU spike, Capacity Metrics app, custom SQL pool, Lakehouse table health.
日本語の概要は準備中です。原文の説明を表示しています。
microsoft/skills-for-fabric☆ 1,2422026年10月5日 更新