Prevent Sql Injection
microsoft/microsoft-sql/plugins/microsoft-sql-vscode/skills/prevent-sql-injectionanalysisResmi
Resmi Sağlayıcı Skill'iView repo
Handles SQL injection on Azure SQL Database beyond parameterisation: a typed sp_executesql parameter matches nothing where the same input concatenated into EXEC() returns every row; QUOTENAME returns NULL above 128 characters, so the batch built from it becomes NULL and does nothing; a dynamic ORDER BY built from one CASE over mixed types fails only for the sort key on the lower-precedence branch; dynamic SQL breaks the ownership chain, so EXECUTE AS decides what it may touch; and Always Encrypt
Dosyalar2 dosya
SKILL.md212 satır
Loading editor…
Kurulum
ÖnerilenTek komut — ajanınız otomatik olarak devreye alır.
Kurulum komutunu görmek için yukarıdan bir AI aracı seçin.
veya
Manuel Kurulum
Daha fazla adımArşivi indirin ve dosyaları projenize manuel olarak ekleyin.
Skill detayları
Versiyonv1.0.0
YazarMicrosoft
Kategorianalysis
Skill IDmicrosoft/microsoft-sql/plugins/microsoft-sql-vscode/skills/prevent-sql-injection
Dosyalar2 dosya
İlgili skill'ler
Analyze Readiness At ScaleUse when analyzing migration assessment readiness at scale or showing an estate-wide migration assessment dashboard for Azure Arc SQL Server instances.Azure Functions Sql BindingsWires Azure Functions to Azure SQL Database with the SQL input and output bindings and the SQL trigger, including the change tracking the trigger cannot run without and the identity permissions the trigger needs beyond the ones the bindings need. Use when a user asks for "a serverless CRUD API over SQL", to "add a SQL input binding", "write to SQL from a function", "react to inserts and updates", "SQL trigger function", "SqlTrigger", "SqlInput", "SqlOutput", or says "my SQL trigger never fires aAzure Functions Sql BindingsWires Azure Functions to Azure SQL Database with the SQL input and output bindings and the SQL trigger, including the change tracking the trigger cannot run without and the identity permissions the trigger needs beyond the ones the bindings need. Use when a user asks for "a serverless CRUD API over SQL", to "add a SQL input binding", "write to SQL from a function", "react to inserts and updates", "SQL trigger function", "SqlTrigger", "SqlInput", "SqlOutput", or says "my SQL trigger never fires aAzure SqlOrients an agent starting work on Azure SQL Database and hands the task to the catalog skill that owns it. Use when someone names the product with no task attached, asks what Azure SQL Database can do, whether a capability is generally available or still preview, which service tier to start on, which tool does a job, or where something is documented. Also use before answering any question about a capability, a default or a limit from memory, because those move faster than training data does. ThiAzuresql Db AuthConnects an app to the Azure SQL Database container securely, with a least-privilege database user instead of the sa login, the right auth method per environment, and safe handling of the connection secret. Use when a user asks "don't use sa in my app", "create a least-privilege database user", "app login for SQL", "which authentication should my app use", "secure the connection string", "Encrypt / TrustServerCertificate", "store the connection string in Key Vault", "dotnet user-secrets", "managAzuresql Db AuthConnects an app to the Azure SQL Database container securely, with a least-privilege database user instead of the sa login, the right auth method per environment, and safe handling of the connection secret. Use when a user asks "don't use sa in my app", "create a least-privilege database user", "app login for SQL", "which authentication should my app use", "secure the connection string", "Encrypt / TrustServerCertificate", "store the connection string in Key Vault", "dotnet user-secrets", "manag