Back to skill

Security audit

Clickhouse Database

Security checks for vulnerabilities and agentic risk

Overview

This ClickHouse helper is not malicious, but it gives an agent live database mutation and credential-handling workflows without enough guardrails.

Install only if you want an agent to operate ClickHouse through clickhouse-client. Use read-only, least-privilege credentials by default; require explicit approval before INSERT, UPDATE, DELETE, DDL, imports, exports, or --multiquery scripts; avoid passing passwords via command arguments; and treat any existing use of those examples as a reason to review logs and rotate credentials if process arguments may have been captured.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:378
Finding

ClickHouse Passwords Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 378 and 403
Vulnerability Type: Credential exposure through process arguments
Risk Level: Medium

The environment-variable and complete-script examples expand ClickHouse passwords directly into the --password command-line argument:

bash
clickhouse-client -h "$CLICKHOUSE_HOST" -u "$CLICKHOUSE_USER" -d "$CLICKHOUSE_DB" --password="$CLICKHOUSE_PASSWORD" -q "SELECT 1;" --format=JSONEachRow
bash
clickhouse-client -h "$DB_HOST" -u "$DB_USER" --password="$DB_PASS" -d "$DB_NAME" -q "$QUERY" --format=JSON 2>&1 | jq .

Technical Analysis

Although the passwords originate in environment variables, shell expansion places their values in the clickhouse-client process argument vector. Depending on the operating system configuration and diagnostic environment, command-line arguments may be visible through process inspection utilities, process metadata interfaces, audit systems, shell tracing, monitoring agents, or collected diagnostic logs.

This guidance also contradicts the security warning at SKILL.md:408, which correctly states that passwords should not be written on the command line because they can be visible in the process list.

An attacker does not need to modify the Skill or inject a command. Exploitation requires the victim to follow one of the affected examples while the attacker or an exposed monitoring system can observe process arguments.

Attack Path

  1. A user stores a valid ClickHouse password in CLICKHOUSE_PASSWORD or DB_PASS.
  2. The user runs one of the documented commands.
  3. The shell expands the variable and passes the plaintext password as part of the process argument vector.
  4. A local user, monitoring agent, audit subsystem, tracing facility, or diagnostic collector captures the process arguments while the client is running.
  5. The observer extracts the ClickHouse username, host, database, and password. ...[truncated 1201 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove --password="$CLICKHOUSE_PASSWORD" and --password="$DB_PASS" from all examples.
  2. Use a ClickHouse client authentication mechanism that does not place the secret in the process argument vector.
  3. Prefer a dedicated ClickHouse client configuration file containing the password, with restrictive permissions:
    bash
    chmod 600 ~/.clickhouse-client/config.xml
    clickhouse-client --config ~/.clickhouse-client/config.xml -q "SELECT 1;"
    
  4. If supported by the deployed client version, use its documented environment-based or interactive password mechanism without copying the value into argv.
  5. Disable shell tracing with set +x before handling credentials, and ensure CI/CD systems and monitoring agents do not record secrets.
  6. Use a dedicated, read-only, least-privilege ClickHouse account for query-only workflows. Use separate narrowly scoped accounts for mutation or administrative tasks.
  7. Require TLS through --secure for production connections so credentials and database traffic are protected in transit.
  8. Rotate credentials if the affected examples have been used in environments where process arguments or command telemetry may have been collected.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill includes destructive INSERT/UPDATE/DELETE guidance, including ALTER TABLE ... DELETE and UPDATE, without a prominent warning, confirmation requirement, or strong distinction between read-only and production-impacting operations. In an agent context, this materially increases the risk of accidental data corruption or deletion if the skill is invoked on live systems or with user-supplied SQL.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description lists activation keywords such as “SQL 语句执行”, “查表”, “查看表结构”, and “大数据查询”, which are generic phrases that could match many ordinary database-related requests rather than a narrowly defined ClickHouse-only intent. The file does not provide exclusion conditions or negative examples to clarify when this skill should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documents redirecting query output to local files and executing multi-statement SQL scripts with --multiquery, but does not prominently warn about file overwrite risks, unintended bulk changes, or the danger of running unreviewed scripts. In an agent-driven workflow, this can amplify accidental destructive actions and make review harder because many changes may occur in one invocation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 411)May include surrounding context.

md
1. **禁止**在命令行中直接写密码(进程列表可见)
2. **使用** `CLICKHOUSE_PASSWORD` 环境变量或配置文件
3. 生产环境**强制**使用 SSL (`--secure` 选项)
4. 配置文件权限设置为 `chmod 600 ~/.clickhouse-client/config.xml`
5. 查询操作使用只读账号
6. 避免使用默认端口和默认用户名/密码

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The stated purpose is ClickHouse database operations via clickhouse-client, which justifies invoking the CLI and connecting to remote databases. However, the documented workflows also include exporting query results to arbitrary local files and feeding SQL from local script files through shell redirection, which expands the skill into generic filesystem manipulation rather than purely database interaction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill recommends creating a persistent local config file containing database credentials, which increases secret exposure risk if the file is reused, copied, backed up, or left with weak permissions. Although the skill later mentions chmod 600, storing plaintext passwords on disk remains more sensitive than ephemeral authentication methods and can lead to credential compromise on shared or poorly managed systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.