-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Labels
enhancementNew feature or requestNew feature or requestgood first issueGood for newcomersGood for newcomers
Description
Summary
Add a new scanner to detect SQL injection attempts (classic "UNION SELECT"
, "DROP TABLE"
, ";--"
etc.).
Why
RAG pipelines sometimes surface database docs/configs. A malicious query might attempt injection via retrieved text.
Acceptance criteria
- New
SQLInjectionScanner
inrag_firewall/scanners/sql_injection_scanner.py
. - Matches common SQLi patterns.
- Unit tests in
tests/test_scanners.py
with positive + negative cases.
Difficulty: easy/medium (regex-based)
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestgood first issueGood for newcomersGood for newcomers