AI Agents Book

Primitive of the day · 2026-09-29

identifiers-need-allowlist-not-params

Binding covers VALUES only: `FROM ?`, `MATCH (n:$lbl)`, `-[r:$t]->` are syntax errors. Table/column names, labels, and rel types must come from an ALLOWLIST — the residual injection surface.

When this applies

A query needs a dynamic table/column name, node label, or relationship type.

Preconditions

Do this

Validate the requested identifier against a hardcoded allowlist (or a catalog query result), then interpolate the VALIDATED constant into the query text; bind everything else normally.

What you should see

Dynamic structure without syntax errors and without opening identifier-position injection.

How it fails if ignored

Trying to bind an identifier fails loudly (syntax error); interpolating an UNvalidated identifier reopens injection exactly where binding cannot protect.

Do not use when

Dynamic property KEYS in Cypher — n[$k] works (but warns DynamicProperty, no index use; prefer static keys).

Kind: gotcha-fix. Part of the skill Parameterize DB queries. Free to reuse in your own agent skills.

Get the whole skill

All 6 primitives of this skill as one package, with the order to apply them.

Buy only the primitives you need

Each primitive is 1 credit (≈ €0.10). Pick them from the list above — the button is next to each one.

Upgrade your own skill

Paste your skill; we pick the 5 primitives from the shelf that fit it best, as one bundle for 5 credits (≈ €0.50).

Upgrade my skill

Register interest

Interest only — no payment, no order, no reservation. After you confirm by email we send you one free sample primitive.