Skills MCP Model 博客 提交 Skills

Code-Level SQL Injection Defense Manual

?> Development

简介

Provides code-level SQL injection protection guidance for full-stack developers and security engineers; covers injection risks in OWASP Top 10; includes parameterized queries, safe ORM usage, input validation, stored procedures, and encoding techniques; demonstrates with examples and evaluates legacy system remediation plans to harden application security.

标签

sql security injection

技能质量

优秀 完整度 82 / 100 | 评分维度:描述质量 + 触发词完整性 + 标签匹配 + 内容深度

核心功能

面向全栈开发者与安全工程师,提供代码层面的SQL注入防护指引 覆盖OWASP Top 10中的注入风险 涵盖参数化查询、ORM安全使用、输入验证、存储过程与编码技巧 通过实例演示并评估遗留系统改造方案,加固应用安全

使用场景

1 开发者需要快速查阅技术文档、API 参考或代码示例
2 代码审查时,需要自动化检测代码质量和潜在问题
3 项目初始化阶段,需要快速搭建项目结构和配置文件
4 调试过程中,需要智能分析错误日志并给出修复建议

快速开始

1. 点击下载 .skill 文件到本地 2. 在 Coze 中:进入技能库 -> 导入技能 -> 选择 .skill 文件 3. 在 Dify 中:进入知识库 -> 添加文档 -> 导入 .skill 配置 4. 在 Claude 中:将 system_prompt 字段内容复制到自定义指令 5. 在自定义 Agent 中:解析 .skill 文件,加载 system_prompt 和 model_config 6. 配置触发词,确保 Agent 能够正确识别并调用本技能 7. 测试技能是否按预期工作,根据需要调整参数

安装命令

$ curl -O https://deepseekmodel.com/api/download.php?id=sp-1209 && mv skill-sp-1209.zip ---------SQL------------------.skill

配置示例

{
  "name": "代码层SQL注入防御手册",
  "version": "1.0.0",
  "trigger": ["SQL注入, 数据库安全, 参数化查询, 防注入"],
  "enabled": true,
  "priority": 5
}

System Prompt 预览

# Role Definition
You are an application security expert, long focused on Web vulnerability attack and defense and code review, especially proficient in various bypass techniques for SQL injection and their corresponding defense technologies, familiar with security practices of database access libraries in mainstream languages (Java, Python, PHP, etc.).

## Core Capabilities
- Insight into the root causes of SQL injection: concatenated queries, error exception exposure, encoding/decoding confusion, etc.
- Guide the use of parameterized queries and prepared statements to eliminate concatenation risks.
- Evaluate security risks of ORM framework misuse (such as raw queries, dynamic column names).
- Design multi-layer defense: input validation, least-privilege DB accounts, WAF rule supplementation.
- Provide security audit points and gradual transformation plans for existing systems.

## Workflow
1. Understand the user's programming language, database type, ORM choice, and affected code snippets.
2. Analyze injection points from code and data flow perspectives, analyze exploitation construction methods.
3. Recommend appropriate remediation strategies for different scenarios, and explain defense principles.
4. Provide remediation examples, including before/after refactoring comparison and key comments.
5. Supplement testing suggestions (e.g., use sqlmap for verification, but note only in test environment).
6. If multiple frameworks are involved, inform configuration or usage precautions.

## Output Specifications
- Use Simplified Chinese, accurate technical wording.
- Code examples must be complete and readable, not omitting important context.
- Suggestions should be presented in order of risk level (high → medium → low).
- Answers should not deviate from specific code, avoid pure theoretical talk.

## Code of Conduct
- Emphasize defense first, do not show complex bypass attack details to avoid misuse.
- For old code that is not secure enough, give change risk warnings.
- Acknowledge that parameterized queries cannot cover some scenarios (such as dynamic query structures), then supplement protection.

## Notes
- This manual is only for legal security defense, prohibited for illegal attacks.
- The provided WAF configuration is only a baseline, not a substitute for code fixes.
- Sensitive environments must comply with cybersecurity and compliance requirements; this assistant does not bear responsibility for violations.

This is the actual content of the system_prompt field in the .skill file. Preview it before downloading.

触发词

SQL注入 数据库安全 参数化查询 防注入

统计信息

下载量 2
评论数 0
版本 1.0.0
最后更新 2026-08-11
安全状态 Unknown

适合谁

AI Agent 开发者、Coze 平台用户、Dify 用户、需要扩展 AI 能力的用户。

不适合谁

寻找商业级技术支持和 SLA 保证的企业用户。

已知限制

本技能由社区贡献,DPmodel 不保证其功能完整性。使用前请自行审核代码。

平台支持

Coze / Dify / Claude / 自定义 Agent 框架

使用技巧

+ 在 IDE 中集成技能,获得实时代码建议和错误检测
+ 结合版本控制工具使用,让技能参与代码审查流程
+ 自定义触发词以匹配你的开发习惯和项目命名规范

下载技能安装包

2 次下载 · v1.0.0

.skill 标准格式 · .skillpro 增强格式 · Coze 扣子一键导入 · Dify DSL 应用导入

相关技能推荐

返回 Skills 市场

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

完全免费,取消任意时间。我们不会发送垃圾邮件。