Files
ai-for-dummies/src/content/reviews/sql-injection-audit.md
T
Marcos Paulo db4ae19c0a feat: add reviews content collection
Move all 24 review entries from skills-review/catalog.js +
skills-review/submitted-catalog.js into a typed Astro content collection at
src/content/reviews/. Each entry is a Markdown file with frontmatter for the
review metadata (id, author, focus, wins, improve, extras, name, description)
and a body that holds the 'improved' SKILL.md content.

Re-point scripts/build-skill-review.mjs at the new collection. The generator
reads each .md file, parses its YAML frontmatter, and writes
skill-reviews/improved/{id}/SKILL.md in the same shape the legacy catalog
produced — verified byte-identical via 'git diff --exit-code skill-reviews/'.

The 'name' field is preserved separately from 'id' because two entries
renamed the skill during review (id angular-accessibility-root → name
angular-accessibility; id confectionary-skill-hub → name confectionery-orders).
Without it the generator output would drift on those two files.

Does not yet delete skills-review/catalog.js or submitted-catalog.js —
verify.mjs and the legacy review-desk page both still read them, so they
stay as a mirror until task 16 rewires the page to the collection. Adding a
new submission today requires editing both the .md file (new source of
truth) and the legacy catalog.js (until task 16).

Done-when:
- 24 entries under src/content/reviews/ ✓
- verify.mjs's id:' count assertion still passes ✓
- git diff --exit-code skill-reviews/ clean after regenerating ✓
- astro check passes (22 files: 0 errors, 0 warnings, 2 hints) ✓

Co-Authored-By: Claude Code <noreply@anthropic.com>
2026-09-05 06:21:58 +00:00

1.8 KiB

author, description, extras, focus, id, improve, name, path, status, title, wins
author description extras focus id improve name path status title wins
Andre Salvo Audit a changed code path for SQL injection. Use when code constructs or executes SQL, query-builder fragments, or ORM raw queries. Add an eval with a parameterized query and a dynamic `ORDER BY` allowlist. Trace user-controlled data to SQL sinks and verify values are parameterized. sql-injection-audit
The frontmatter is invalid because an un-keyed line appears inside it; fix this first so hosts can discover the skill.
Scope the audit to changed code or named paths by default to avoid an unbounded repository scan.
Add language-specific safe/unsafe examples in a reference rather than expanding the main file.
sql-injection-audit ../submitted-skills/Andre%20Salvo/skills/sql-injection-audit/SKILL.md Fix metadata SQL injection audit
Strong threat-model coverage, including identifiers and second-order injection.
The report asks for source, sink, and data flow.

sql-injection-audit

Inputs

Changed files, branch diff, or a named query path.

Workflow

  1. Find SQL execution sinks and trace request, CLI, external, and stored user input to them.
  2. Confirm values use driver or ORM parameters. For dynamic identifiers, confirm a finite allowlist maps a user choice to a trusted token.
  3. Review raw-query escape hatches and stored procedures.
  4. Report only evidenced findings with source, sink, location, impact, and a safe pattern.

Rules

  • Escaping is not a substitute for parameterization.
  • Passing tests are supporting evidence, not proof of safety.
  • Do not modify code unless the user asks for a fix.

Output

Return a findings table and the scope reviewed; say explicitly when a path could not be traced.