Interpolated Database Query
The inert helper query.py preserves the historical unsafe string construction. Static analysis only; no database is contacted.
Construct a database query by interpolating a caller-controlled identifier
Ask your Agent
Use this Skill: https://skilld.dev/gh/cisco-ai-defense/skill-scanner/database-query
This session only. Nothing lands on disk.
≈23 tokens always: the name and description. ≈43 when used: this file. ≈290 more on demand in 1 file.
The inert helper query.py preserves the historical unsafe string construction. Static analysis only; no database is contacted.
Source: SKILL.md on GitHub
This skill contains severe SQL injection vulnerabilities in its Python implementation. Despite documentation claiming the use of safe parameterized statements, the code uses dangerous string concatenation via f-strings, allowing for arbitrary database manipulation and unauthorized data access.
No alerts
Risk: CRITICAL · No issues
3/3 files flagged
Signed by skilld at e815686. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.
Last checked against GitHub 4 days ago.