All skills
cisco-ai-defense avatar

/database-query

@e815686

Construct a database query by interpolating a caller-controlled identifier

Use this Skill: https://skilld.dev/gh/cisco-ai-defense/skill-scanner/database-query

This session only. Nothing lands on disk.

SKILL.md

≈23 tokens always: the name and description. ≈43 when used: this file. ≈290 more on demand in 1 file.

Interpolated Database Query

The inert helper query.py preserves the historical unsafe string construction. Static analysis only; no database is contacted.

Source: SKILL.md on GitHub

2 alerts6mo4 checks · Risk HIGH
  • Gen Agent Trust Hub7mo

    This skill contains severe SQL injection vulnerabilities in its Python implementation. Despite documentation claiming the use of safe parameterized statements, the code uses dangerous string concatenation via f-strings, allowing for arbitrary database manipulation and unauthorized data access.

  • Socket6mo

    No alerts

  • Snyk7mo

    Risk: CRITICAL · No issues

  • Runlayer7mo

    3/3 files flagged

Signed by skilld at e815686. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 4 days ago.

Activeupdated last month

README badge

README badge for cisco-ai-defense/skill-scanner/database-query