T09 · Insecure Skill Coding Practices
- Location
SKILL.md:298- Finding
SQL Injection and Unsafe Filename Handling in Migration Script
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 fi already=$( psql "$DB_URL" -v version="$version" -tAc \ "SELECT 1 FROM schema_migrations WHERE version = :'version';" ) if [ "$already" = "1" ]; then printf 'SKIP: %s (already applied)\n' "$version" continue fi psql "$DB_URL" -v ON_ERROR_STOP=1 -f "$file" && psql "$DB_URL" -v ON_ERROR_STOP=1 -v version="$version" -c \ "INSERT INTO schema_migrations (version) VALUES (:'version');" done ``` If ordering is required, generate a safely sorted, null-delimited list rather than relying on `ls` and shell word splitting. ]]>
