Primitive of the day · 2026-09-29
identifiers-need-allowlist-not-params
Binding covers VALUES only: `FROM ?`, `MATCH (n:$lbl)`, `-[r:$t]->` are syntax errors. Table/column names, labels, and rel types must come from an ALLOWLIST — the residual injection surface.
When this applies
A query needs a dynamic table/column name, node label, or relationship type.
Preconditions
- The set of legal identifiers is finite and known
Do this
Validate the requested identifier against a hardcoded allowlist (or a catalog query result), then interpolate the VALIDATED constant into the query text; bind everything else normally.
What you should see
Dynamic structure without syntax errors and without opening identifier-position injection.
How it fails if ignored
Trying to bind an identifier fails loudly (syntax error); interpolating an UNvalidated identifier reopens injection exactly where binding cannot protect.
Do not use when
Dynamic property KEYS in Cypher — n[$k] works (but warns DynamicProperty, no index use; prefer static keys).
Kind: gotcha-fix. Part of the skill Parameterize DB queries. Free to reuse in your own agent skills.
Get the whole skill
All 6 primitives of this skill as one package, with the order to apply them.
Buy only the primitives you need
Each primitive is 1 credit (≈ €0.10). Pick them from the list above — the button is next to each one.
Upgrade your own skill
Paste your skill; we pick the 5 primitives from the shelf that fit it best, as one bundle for 5 credits (≈ €0.50).
Upgrade my skill