T09 · Insecure Skill Coding Practices
- Location
scripts/sql.sh:454- Finding
Unsanitized table identifiers allow injection into generated SQL
- Content
View full analysis
- Remediation
View remediation
&2 return 1 fi } ``` 2. Call the validator for all table names before any output is produced: ```bash validate_identifier "$table" || exit 2 ``` 3. Apply database-specific identifier quoting after validation: - MySQL and MariaDB: backticks - PostgreSQL and SQLite: double quotes 4. Do not rely on quoting alone. Reject delimiter characters, whitespace, semicolons, comments, control characters, and qualified identifiers unless explicitly supported and validated component by component. 5. Clearly label generated SQL as untrusted output that must be reviewed before execution. 6. Add regression tests using malicious identifiers containing backticks, quotes, semicolons, comment markers, newlines, and whitespace. 7. If generated SQL is ever executed automatically, use a database API that safely composes identifiers and run it through a minimally privileged database account. ]]>
