github / github/copilot-cli

SQL tool invoke filters "attach" in the text of the value being inserted

Đang mở
#2,221 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
area:tools
Ngôn ngữ chính
Shell
Star
11.2k
Fork
1.9k
Merge trung bình
14 giờ 16 phút
Pull request đã merge (30 ngày)
6

Mô tả

### Describe the bug

```

✗ Store identify review results (sql)
│ INSERT INTO trace_reviews (trace, function_name, file, status, finding) VALUES
└ Blocked SQL statement: "attach" is not allowed for security reasons.

```
I saw the above error in the trace of my agent using sql to track the status of a code review.

The model said this:
```
● The word "attach" in data triggers the filter. Let me split the inserts:
```

Looks like there needs to be some better filtering of commands versus values when evaluating the safety of sql statements. Maybe ask sqlite-ast-parser to parse the statement first and then evaluate the different parts of the statement? Or use `sqlite3_set_authorizer` to inspect commands as they execute.

### Affected version

GitHub Copilot CLI 1.0.10

### Steps to reproduce the behavior

I asked for a trace-by-trace code review of a codebase via claude opus 4.6. It chose to use a sqlite database to track status of review. the codebase contains the word attach in its functions.

### Expected behavior

_No response_

### Additional context

_No response_

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.