No. Use parameterized SQL even for internal values, because runtime data can drift or be malformed and f-string SQL creates an injection-prone boundary. Keep the query text fixed and pass values through the driver parameters.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add HoangNguyen0403/agent-skills-standard --skill python-database --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Python Database?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-python-database)More formats (shields.io, HTML) on the badges page.
No. Use parameterized SQL even for internal values, because runtime data can drift or be malformed and f-string SQL creates an injection-prone boundary. Keep the query text fixed and pass values through the driver parameters.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!