Security
检测输入字符串中的常见SQL注入攻击模式
用三种语言从你的代码中调用此工具。
curl -X POST 'https://api.elysiatools.com/zh/api/tools/sql-injection-detector' \
-H 'Content-Type: application/json' \
-d '{"text":"Enter text or code to scan for SQL injection patterns...","caseSensitive":false,"checkComments":true,"checkUnion":true,"checkTimeBased":true,"checkBoolean":true,"whitelist":"Comma-separated patterns to whitelist (e.g., SELECT user_id FROM users)"}'以 JSON 形式 POST 提交输入参数。文件类型参数需先单独上传。
POST https://api.elysiatools.com/zh/api/tools/sql-injection-detector| 参数名 | 类型 | 必填 | 说明 |
|---|---|---|---|
| text | textarea | 是 | — |
| caseSensitive | checkbox | 否 | Enable case-sensitive pattern matching |
| checkComments | checkbox | 否 | Detect SQL comment patterns (--, /*, */, #) |
| checkUnion | checkbox | 否 | Detect UNION-based SELECT injection |
| checkTimeBased | checkbox | 否 | Detect time-based injection (WAITFOR DELAY, SLEEP, BENCHMARK) |
将此工具加入你的 Model Context Protocol 服务,让 AI 智能体可以列出并调用它。
将以下内容加入你的 MCP 客户端配置:
{
"mcpServers": {
"elysiatools-sql-injection-detector": {
"name": "sql-injection-detector",
"description": "检测输入字符串中的常见SQL注入攻击模式",
"baseUrl": "https://api.elysiatools.com/mcp/sse?toolId=sql-injection-detector",
"command": "",
"args": [],
"env": {},
"isActive": true,
"type": "sse"
}
}
}连接到 SSE 端点后,列出已开放的工具:
{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/list"
}通过工具 id 调用,参数由其参数表构建:
{
"jsonrpc": "2.0",
"id": 2,
"method": "tools/call",
"params": {
"name": "sql-injection-detector",
"arguments": {
"text": "Enter text or code to scan for SQL injection patterns...",
"caseSensitive": false,
"checkComments": true,
"checkUnion": true,
"checkTimeBased": true,
"checkBoolean": true,
"whitelist": "Comma-separated patterns to whitelist (e.g., SELECT user_id FROM users)"
}
}
}有问题或反馈?请联系 [email protected]
| checkBoolean | checkbox | 否 | Detect boolean-based injection patterns |
| whitelist | text | 否 | Patterns that should be considered safe (comma-separated) |
JSON 结果
{
"key": {...},
"metadata": {
"key": "value"
},
"error": "Error message (optional)",
"message": "Notification message (optional)"
}