Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- Database selection by case-insensitive partial name matching is unsafe because an ambiguous or attacker-influenced prompt can resolve to the wrong configured database. In this skill, that could cause SQL intended for a test system to run against production, potentially exposing, modifying, or deleting sensitive data.
