Because if you use the input parameters correctly they are immune to injection.
If you concatenate unsanitized input you are susceptible no matter where you write the SQL.
If you concatenate unsanitized input you are susceptible no matter where you write the SQL.