skills/kevintsengtw/dotnet-testing-agent-skills/dotnet-testing-advanced-webapi-integration-testing/Gen Agent Trust Hub
dotnet-testing-advanced-webapi-integration-testing
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEDYNAMIC_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
DatabaseManager.cstemplate intemplates/database-manager.cscontains a SQL injection vulnerability in theSeedProductAsyncmethod. It uses string interpolation to build a SQL query ($"INSERT INTO products ... VALUES ('{id}', '{name}', {price}, ...)") using thenameparameter directly. An attacker providing a malicious string for the product name could execute arbitrary SQL commands against the test database. - [DYNAMIC_EXECUTION]: The
DatabaseManager.csimplementation dynamically loads and executes SQL scripts from the file system within theEnsureTablesExistAsyncmethod. It reads files from aSqlScriptsdirectory relative to the application's base directory and executes them usingNpgsqlCommand. This creates a dependency on the integrity of the local file system where a compromised script file would result in arbitrary database command execution.
Audit Metadata