Discover MCPs & agents
Loading MCPs and agents…
Loading MCPs and agents…
SQLMap with Autonomous AI, phased workflows, RAG memory, and MCP Agent Tools
From the repo.
AI-assisted SQLMap orchestration + real-time dashboard + MCP tool server (agent-ready)
A guided, repeatable workflow: Targets → Preflight → Phased Scan → AI Assist → Evidence → Report
✅ Renamed branding from Intelligence → Autonomous AI
✅ Added MCPFast (FastMCP) command-line usage (No UI required)
✅ MCP supports URL scan and targetlist (.txt) scan
✅ Best for Windows + Linux servers (headless / no GUI)
SQLMAP SKYNET wraps sqlmap.py with a Neural Ops workflow — fast, structured, and trackable.
Goal: higher signal, less noise, and reports real proof.
flowchart TD
A["1. Targets<br/>single URL or list"] --> B["2. Preflight<br/>GET or POST + headers + cookies + safe limits"]
B --> C["3A. Dashboard Control<br/>FastAPI UI + WebSocket"]
B --> D["3B. MCP Control<br/>Agent tool calls"]
C --> E["4. Runner Core<br/>SQLMapRunner -> SQLMapBackend -> sqlmap.py"]
D --> E
E --> F["5A. Autonomous AI<br/>Ollama first, cloud fallback"]
E --> G["5B. RAG Memory<br/>learn + recall"]
E --> H["5C. Web Intel<br/>optional search"]
E --> I["5D. WAF Intel<br/>fingerprint + bypass hints"]
F --> J["6. Artifacts<br/>reports + logs + sessions"]
G --> J
H --> J
I --> J
J --> K["7. View or Export<br/>Dashboard + files"]
flowchart TD
subgraph INPUT["INPUT"]
T["Targets"] --> PF["Preflight"]
end
subgraph CONTROL["CONTROL"]
UI["Dashboard"] --- MCP["MCP Client"]
end
subgraph ENGINE["ENGINE"]
RUN["Runner Core"] --> SM["sqlmap.py"]
end
subgraph INTEL["INTEL"]
AI["Autonomous AI"] --- RAG["RAG Memory"] --- WEB["Web Intel"] --- WAF["WAF Intel"]
end
subgraph OUTPUT["OUTPUT"]
ART["Artifacts"] --> REP["Reports"]
end
PF --> CONTROL
CONTROL --> ENGINE
ENGINE <--> INTEL
ENGINE --> OUTPUT
Key idea: MCP and Dashboard are two ways to drive the same engine logic:
![]() | ![]() |
![]() | ![]() |
![]() | ![]() |
sqlmap.py present (recommended: .\sqlmap\sqlmap.py)Use Cloud AI (OpenAI / Groq / DeepSeek / Kimi / Claude) or run with AI features OFF.
llama3.2:latest)Tip: Llama 3.2 in Ollama has small variants (1B/3B). If your PC is weak, local AI still works — just expect slower responses.
Open PowerShell:
git clone https://github.com/drcrypterdotru/sqlmap-skynet
cd sqlmap-skynet
py -3.12 -m venv .venv
.\.venv\Scripts\Activate.ps1
python --version
pip install -U fastapi uvicorn python-dotenv aiohttp requests numpy scikit-learn
Optional (for MCP server over HTTP):
pip install -U fastmcp
.envCopy-Item .env.example .env
Open .env and set what you need:
Best practice (inside project folder):
git clone https://github.com/sqlmapproject/sqlmap.git sqlmap
✅ You must have:
sqlmap-skynet\
sqlmap\sqlmap.py
main.py
config.py
...
ollama --version
Your config.py sets:
OLLAMA_MODELS['default'] = 'llama3.2:latest'Pull it:
ollama pull llama3.2:latest
Test:
ollama run llama3.2:latest
If you want to switch model later, edit
config.pyunderOLLAMA_MODELS.
Start the server:
python main.py --host 0.0.0.0 --port 1337 --debug
Open:
http://127.0.0.1:1337Use a target you own / have permission to test.
In the dashboard:
Choose safe defaults:
max_cycles = 30Then click Start.
After the scan:
sqlmap_reports\memory\sessions\ (if RAG enabled)MCP allows an AI agent to call SKYNET tools:
sqlmap_scan → starts scan (uses sqlmap.py)get_scan_status → polling status/resultsget_ai_providers → shows available AI backendspip install -U fastmcp
Run in a new PowerShell (keep dashboard in another terminal if you want both):
fastmcp run .\mcp\server.py:mcp --transport http --host 127.0.0.1 --port 8055
Your MCP endpoint:
http://127.0.0.1:8055/mcpfastmcp list http://127.0.0.1:8055/mcp
✅ Yes. MCP tool sqlmap_scan creates SQLMapRunner("sqlmap.py"), and the runner uses core/autonomous_ai.py.
So MCP calls automatically use your Autonomous AI + RAG logic (no module changes needed).
Sometimes you don’t want the dashboard (example: Linux server / VPS / headless box).
You can run SKYNET fully from command line using FastMCP — perfect when you don’t have a GUI.
Open terminal in project root:
fastmcp run .\mcp\server.py:mcp --transport http --host 127.0.0.1 --port 8055
MCP endpoint:
http://127.0.0.1:8055/mcpRun these commands (this is the fastest proof MCP is healthy):
fastmcp list http://127.0.0.1:8055/mcp --auth none
fastmcp call http://127.0.0.1:8055/mcp get_ai_providers --auth none
fastmcp call http://127.0.0.1:8055/mcp get_scan_status --auth none
What you should see
sqlmap_scan, get_scan_status, get_ai_providersollama (recommended)running=false until you start a scanfastmcp call http://127.0.0.1:8055/mcp sqlmap_scan --auth none ^
url="http://testphp.vulnweb.com/artists.php?artist=1" ^
method="GET" ^
max_cycles=10 ^
ai_provider="ollama"
Create target.txt in project root (one URL per line), then:
fastmcp call http://127.0.0.1:8055/mcp sqlmap_scan --auth none ^
targetlist="target.txt" ^
method="GET" ^
max_cycles=10 ^
ai_provider="ollama"
Tip:
targetlistshould be inside the project folder for safety.
If you can't run Ollama fast (low RAM/CPU), you can use Cloud AI.
.envOPENAI_API_KEY=YOUR_KEY_HERE
Other supported keys:
GROQ_API_KEY=...DEEPSEEK_API_KEY=...KIMI_API_KEY=...ANTHROPIC_API_KEY=...SKYNET will detect which providers are available and use them when needed.
Provider priority is defined in
config.pyasAI_PRIORITY.
config.py is the brains + intel database of SKYNET.
If you want better results, this is the first file to tune.
Tip: On GitHub you can click the file:
config.py→ then use the browser search (Ctrl+F) for the section names below.
⚠️ For educational/authorized testing only. Use only on systems you own or where you have written permission.
SKYNET reads the local Ollama model name from:
OLLAMA_MODELS = {"default": "llama3.2:latest"}
What to do:
llama3.2:latest as default if it works well on your PC.Why it matters: model choice affects speed + quality of AI plans.
Example:
AI_PRIORITY = ["ollama","deepseek","kimi","groq","openai","claude"]
What to do:
ollama first.Why it matters: the first available provider in this list is used most often.
This section is like a “bypass playbook”.
It stores presets for common conditions like:
Typical preset contains:
delay and timingthreads (lower threads = less blocks)tamper_scripts (safe → aggressive)How SKYNET uses it:
Operator tip:
Tamper scripts can help evade filters but they can also:
SKYNET organizes them into groups like:
basicmoderateaggressivewaf_specificBest practice:
This controls which SQLi techniques SKYNET tries to focus on first (depending on your logic).
Typical techniques:
Why it matters:
On many real targets, hammering time-based from the start creates slow scans + blocks.
A good priority order can produce faster confirmation and cleaner results.
This is one of the strongest “operator experience” features.
HIGH_VALUE_COLUMNS contains keywords like:
password, pass, hashemail, phonetoken, apikey, secretsession, cookiecard, cc, billingadmin, role, permissionHow SKYNET uses it:
Customize it for your environment Add your own keywords, for example:
employee_id, salary, departmentinvoice, receipt, balanceorder_id, shipment, carttelegram, line_id, customer_uidBig win: better keyword intel = faster identification of “real impact” in a report.
Depending on your version, you may also see:
If you’re unsure: keep defaults and tune slowly.
If you want users to click from README:
config.py (example):
./config.pyExample you can paste anywhere in README:
See: [config.py](./config.py)
sqlmap-skynet/
├─ 🚀 main.py
│ └─ FastAPI dashboard server + WebSocket control + scan orchestration
├─ 🧠 config.py
│ └─ AI models + provider priority + WAF bypass packs + tamper DB + keyword intel
├─ 🧩 api.py
│ └─ (optional/legacy) stats endpoint helper (older Flask-based helper)
├─ 🧪 .env / .env.example
│
├─ 🛠️ scanners/
│ ├─ 🧭 runner.py
│ │ └─ Phase engine (detect → bypass → enumerate → dump) + session state
│ └─ 🧱 sqlmap_backend.py
│ └─ Builds and executes real `sqlmap.py` commands
│
├─ 🧠 core/
│ ├─ 🤖 autonomous_ai.py
│ │ └─ AI planner + provider health + JSON plan parsing
│ ├─ 🧬 rag_memory.py
│ │ └─ Store/recall session intelligence (learn from past scans)
│ ├─ 🧾 report_generator.py
│ │ └─ Build artifacts/reports from results
│ ├─ 📡 state_manager.py
│ │ └─ Shared runtime state (running/progress/results)
│ ├─ 🛡️ waf_intel.py
│ │ └─ WAF fingerprinting + mutation ideas + learning profile
│ └─ 🧿 debug_logger.py
│ └─ Colored logs + structured tags
│
├─ 🔎 search/
│ └─ 🌐 web_search.py
│ └─ Optional web intel lookup + caching
│
├─ 🔌 mcp/
│ └─ 🛰️ server.py
│ └─ MCP tool server (sqlmap_scan, get_scan_status, get_ai_providers)
│
├─ 🧰 utils/
│ ├─ 🗂️ file_browser.py
│ │ └─ Safe file browsing inside project root (UI file picker)
│ └─ 🧩 parsers.py
│
├─ 🎛️ templates/
│ └─ 🖥️ dashboard.html
├─ 🎨 static/
│ └─ ⚙️ js/stats.js
│
├─ 🧠 memory/
│ ├─ 🧾 sessions/
│ │ └─ RAG memory snapshots (per scan)
│ ├─ 🗃️ search_cache/
│ │ └─ cached web intel queries
│ └─ 🧠 *_patterns.json
│ └─ learned patterns + bypass intelligence
│
└─ 📦 sqlmap_reports/
└─ generated scan reports (html/json/txt depending on run)
Where your outputs go:
sqlmap_reports\ → scan reports (proof + export)memory\sessions\ → RAG snapshots per sessionmemory\search_cache\ → cached web intel resultsmemory\*_patterns.json → learned patterns and bypass infoJoin Telegram: https://t.me/burnwpcommunity
Website: https://drcrypter.net
More tools, resources, and updates are shared on the website + community.
We welcome contributions! Feel free to fork this repository, make enhancements, and open pull requests. Please check the issues page for ongoing tasks or bug reports.
This project is licensed under the MIT License. See the LICENSE file for details.
This tool is for educational purposes only. 🏫 The creator and contributors are not responsible for any misuse or damages caused. Use responsibly, and only on systems you own or have permission for. ✅