SQL injection in user search
An AI assistant produced this Python Flask endpoint to search users by name. It runs and returns results in the happy path. What's wrong with it, what input breaks it, and how would you catch this class of bug on AI-generated code?
Implement
build_search_query(name: str) → list[str]Examples
in
["ada"]out["SELECT id, email FROM users WHERE name LIKE ? ESCAPE '!'","%ada%"]in
["' OR '1'='1"]out["SELECT id, email FROM users WHERE name LIKE ? ESCAPE '!'","%' OR '1'='1%"]in
["50%_off"]out["SELECT id, email FROM users WHERE name LIKE ? ESCAPE '!'","%50!%!_off%"]What a strong answer looks like
Treat the AI’s output as a draft to verify, not an answer to trust. Name the specific flaw and the input that triggers it, say how you’d catch it (tests, edge cases, reading critically), and how you’d re-prompt or decompose to get it right.
0:00 of about 16 min
Vibe & agentic: describe the solution in plain language (or narrate it) and the coach grades your approach.
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.