Review agent · Web & injection

SQL injection

Decides whether attacker-controlled input actually reaches a SQL or NoSQL query unparameterized.

api/users.py1uid = request.args["id"]2sql = f"SELECT * FROM users3 WHERE id = {uid}"4db.execute(sql)SQLiwhat this review answersDoes request input reach the query?Is the value bound as a parameter?Constant or server-side config?$ verdict REAL ISSUE$ fix use a parameterized query▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

Injection is one of the oldest bug classes and still one of the most damaging: a single injectable query can expose or rewrite an entire database. It sits under OWASP Top 10 A03 (Injection) and CWE-89 is a fixture of the CWE Top 25.

It is also one of the noisiest for scanners. Pattern rules flag every string-built query, including ones built from constants or already-bound parameters. This agent traces whether the value is really user-controlled and whether it is bound before the sink, so your team stops re-reviewing safe ORM code.

What it checks

  • Queries built with f-strings, concatenation or .format()
  • ORM escape hatches used unsafely — text(), raw(), execute() with interpolated values
  • Dynamic table or column names taken from input
  • NoSQL / Hibernate query construction from request data

When it marks a finding as a likely false positive

  • The value is bound as a query parameter before execution
  • The interpolated value is a constant or comes from server-side config

The fix it suggests

  • Parameterized / prepared statements or the ORM's safe query API
  • An allow-list for dynamic identifiers that cannot be bound
  • Never ad-hoc escaping

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Does the SQL injection agent flag every raw query?

No. It reviews each scanner finding and marks it a likely false positive when the value is a constant or is bound as a parameter, explaining what makes it safe.

Does it cover NoSQL injection?

Yes. CWE-943 (improper neutralization in data query logic) is routed to this agent, which covers MongoDB-style operator injection as well as SQL.

Related agents

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the SQL injection agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free