ProfessorGPTProfessorGPT
Official Provider SkillView repo

Handles SQL injection on Azure SQL Database beyond parameterisation: a typed sp_executesql parameter matches nothing where the same input concatenated into EXEC() returns every row; QUOTENAME returns NULL above 128 characters, so the batch built from it becomes NULL and does nothing; a dynamic ORDER BY built from one CASE over mixed types fails only for the sort key on the lower-precedence branch; dynamic SQL breaks the ownership chain, so EXECUTE AS decides what it may touch; and Always Encrypt

Files2 files
SKILL.md212 lines
Loading editor…

Install

Recommended

One command — your agent picks it up automatically.

Select an AI agent above to see the install command.

or

Manual Install

More steps

Download the archive and add the files to your project manually.

Skill details

Versionv1.0.0
AuthorMicrosoft
Categoryanalysis
Skill IDmicrosoft/microsoft-sql/plugins/microsoft-sql-vscode/skills/prevent-sql-injection
Files2 files

Related skills

Analyze Readiness At ScaleUse when analyzing migration assessment readiness at scale or showing an estate-wide migration assessment dashboard for Azure Arc SQL Server instances.Azure Functions Sql BindingsWires Azure Functions to Azure SQL Database with the SQL input and output bindings and the SQL trigger, including the change tracking the trigger cannot run without and the identity permissions the trigger needs beyond the ones the bindings need. Use when a user asks for "a serverless CRUD API over SQL", to "add a SQL input binding", "write to SQL from a function", "react to inserts and updates", "SQL trigger function", "SqlTrigger", "SqlInput", "SqlOutput", or says "my SQL trigger never fires aAzure Functions Sql BindingsWires Azure Functions to Azure SQL Database with the SQL input and output bindings and the SQL trigger, including the change tracking the trigger cannot run without and the identity permissions the trigger needs beyond the ones the bindings need. Use when a user asks for "a serverless CRUD API over SQL", to "add a SQL input binding", "write to SQL from a function", "react to inserts and updates", "SQL trigger function", "SqlTrigger", "SqlInput", "SqlOutput", or says "my SQL trigger never fires aAzure SqlOrients an agent starting work on Azure SQL Database and hands the task to the catalog skill that owns it. Use when someone names the product with no task attached, asks what Azure SQL Database can do, whether a capability is generally available or still preview, which service tier to start on, which tool does a job, or where something is documented. Also use before answering any question about a capability, a default or a limit from memory, because those move faster than training data does. ThiAzuresql Db AuthConnects an app to the Azure SQL Database container securely, with a least-privilege database user instead of the sa login, the right auth method per environment, and safe handling of the connection secret. Use when a user asks "don't use sa in my app", "create a least-privilege database user", "app login for SQL", "which authentication should my app use", "secure the connection string", "Encrypt / TrustServerCertificate", "store the connection string in Key Vault", "dotnet user-secrets", "managAzuresql Db AuthConnects an app to the Azure SQL Database container securely, with a least-privilege database user instead of the sa login, the right auth method per environment, and safe handling of the connection secret. Use when a user asks "don't use sa in my app", "create a least-privilege database user", "app login for SQL", "which authentication should my app use", "secure the connection string", "Encrypt / TrustServerCertificate", "store the connection string in Key Vault", "dotnet user-secrets", "manag