interpolated-database-query
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
build_queryfunction inquery.pyimplements an unsafe string interpolation pattern to construct database queries, making it vulnerable to injection attacks. - Ingestion points: The
user_idparameter in thebuild_queryfunction (query.py) serves as the ingestion point for untrusted, caller-controlled data. - Boundary markers: The skill lacks any boundary markers or delimiters to separate the user-provided data from the SQL command structure, allowing for command confusion.
- Capability inventory: The skill is specifically designed to generate database query strings. While it does not execute them internally, it creates the capability for downstream tools to execute potentially malicious SQL.
- Sanitization: There is no evidence of input validation, sanitization, or the use of parameterized queries (prepared statements). The code uses Python f-strings to directly embed the
user_idinto the query string.
Audit Metadata