Back to skills directory

SQL Injection Review

New

把字符串拼接 SQL 标成缺陷,要求参数绑定,并举例说明 ORM 仍可能拼接。

SQL Injection Review is an Agent skill for Security. 把字符串拼接 SQL 标成缺陷,要求参数绑定,并举例说明 ORM 仍可能拼接。 Tags: SQL 注入 · OWASP · 绑定参数.

SecurityAuthor: 编辑整理Visit

What is SQL Injection Review

SQL Injection Review packages a Security workflow for agents. 把字符串拼接 SQL 标成缺陷,要求参数绑定,并举例说明 ORM 仍可能拼接。

Install SQL Injection Review in Cursor / Claude / Codex

Claude Code Install with the command on this page, or place the skill in ~/.claude/skills or project .claude/skills so Claude can detect SQL Injection Review.

Cursor After the install command writes the skill directory, invoke SQL Injection Review by name in the Cursor agent.

Codex Install into the Codex skills directory and call it by name. If only a generic command is listed, run it locally and confirm Codex can see the skill.

This page has no install command. Check the project home for how to install SQL Injection Review.

Please visit the Project Home to see installation and usage instructions.

How to Use

Claude Code: Place the skill in ~/.claude/skills (personal) or the project .claude/skills directory, and Claude will auto-detect it.

Cursor / Windsurf: After installing via npx skillsadd, the skill directory is placed in the configured path.

Codex CLI: After installation it loads automatically from the skills directory and is invoked by name.

Tags

SQL 注入OWASP绑定参数

Similar recommendations

FAQ

What is SQL Injection Review for?

SQL Injection Review is a Security skill. 把字符串拼接 SQL 标成缺陷,要求参数绑定,并举例说明 ORM 仍可能拼接。

Can Claude, Cursor, and Codex all use SQL Injection Review?

Yes if the client supports Agent Skills and has loaded the skill directory. Check the project home for compatibility notes.

What similar skills exist?

Related items come from the same Security group so you can pick a closer workflow.