Back to skill

Security audit

MySQL Database CLI Skill

Security checks for vulnerabilities and agentic risk

Overview

This MySQL skill is coherent, but it gives broad database write, bulk import/export, script execution, and credential-handling guidance without enough safety scoping for production or sensitive databases.

Review carefully before installing. Use this only with explicit user-directed database targets, least-privilege accounts, reviewed SQL, staging or backups for writes, and safer secret handling such as interactive prompts, mysql_config_editor, or an approved secret manager. Avoid using it against production databases unless the agent is required to ask for confirmation before any write, import, export, schema, script, or admin action.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:66
Finding

Insecure Database Credential Storage and TLS Configuration Guidance

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 66–119 and 431–466
Vulnerability Type: Insecure credential handling and transport configuration
Risk Level: Medium

Vulnerable Code

bash
MYSQL_PWD=yourpassword mysql -h 127.0.0.1 -u app_user --database app_db -s -r
bash
MYSQL_PWD=password mysql -h 192.168.1.100 -P 3306 -u admin --database mydb --ssl-mode=REQUIRED --connect-timeout=10 -s -r
ini
[client]
host = 127.0.0.1
port = 3306
user = app_user
database = app_db
password = yourpassword
ssl-mode = DISABLED
bash
export MYSQL_PWD="yourpassword"
export MYSQL_HOST="127.0.0.1"
export MYSQL_USER="app_user"
export MYSQL_DATABASE="app_db"

mysql -s -r -e "SELECT 1;"

The security guidance subsequently recommends the same environment-variable mechanism:

text
2. Use the MYSQL_PWD environment variable or a configuration file

Technical Analysis

The Skill presents MYSQL_PWD and a plaintext MySQL option file as preferred credential-handling mechanisms. Passwords stored in environment variables can be inherited by child processes and may be exposed through diagnostic tools, process inspection available to sufficiently privileged local users, crash reports, debugging output, or accidental environment logging. A plaintext option file similarly exposes a reusable database credential if file permissions, backups, or host access are not adequately controlled.

The sample option file also sets ssl-mode = DISABLED. If this configuration is adapted for a non-local connection, MySQL credentials, queries, and returned data may traverse the network without authenticated encryption. The later recommendations to require TLS in production and apply mode 600 to the option file reduce risk but contradict the insecure examples and do not prevent users or agents from copying them directly.

No real password is embedded in the repository—the displayed va ...[truncated 1642 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove ssl-mode = DISABLED from all examples. For remote connections, use --ssl-mode=VERIFY_IDENTITY with a trusted CA certificate and hostname verification.
  2. Do not describe MYSQL_PWD as the preferred secure mechanism. Prefer interactive password prompting, an approved secret manager, short-lived credentials, or mysql_config_editor.
  3. If an option file is unavoidable, create it with restrictive permissions before writing credentials, keep it outside shared locations, exclude it from source control and backups where appropriate, and document secure deletion and rotation procedures.
  4. Use dedicated credentials with the minimum necessary database privileges and limited network origin rules.
  5. Avoid exporting credentials globally. Pass secrets through a narrowly scoped, protected mechanism and ensure they are not inherited by unrelated child processes.
  6. Add explicit warnings that sample values must never be replaced with production secrets in shell history, checked-in scripts, logs, or broadly readable files.
  7. Rotate credentials immediately if they are suspected to have appeared in logs, diagnostics, process environments, or exposed configuration files.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:71
Finding

Remote Database Connection Example Defaults to the MySQL Root Account

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 71–85
Vulnerability Type: Excessive database privilege and unsafe administrative default
Risk Level: Low

Vulnerable Code

bash
# Example: build a connection from a JDBC URL
JDBC_URL="jdbc:mysql://nexus.syrinxchina.com:3306/test3"
HOST=$(echo $JDBC_URL | sed -n 's/.*:\/\/\([^:]*\):\([0-9]*\)\/\(.*\)/\1/p')
PORT=$(echo $JDBC_URL | sed -n 's/.*:\/\/\([^:]*\):\([0-9]*\)\/\(.*\)/\2/p')
DB=$(echo $JDBC_URL | sed -n 's/.*:\/\/\([^:]*\):\([0-9]*\)\/\(.*\)/\3/p')
mysql -h "$HOST" -P "$PORT" -u root --database "$DB" -s -r

Technical Analysis

The JDBC parsing example connects to the resulting remote host as the MySQL root user, even though parsing a connection string and performing routine database operations do not inherently require administrative privileges. This violates least-privilege principles and encourages use of a highly privileged account for ordinary queries.

The Skill supports data modification, deletion, schema management, script execution, import, and export. Running those operations through an administrative account substantially increases the consequences of an accidental query, compromised credential, malicious SQL script, or incorrectly interpreted user request.

The example does not itself bypass authentication or elevate an existing account. The risk arises when an operator follows the documented default and supplies root credentials, unnecessarily placing server-wide administrative privileges in the execution path.

Attack Path

  1. A user or agent parses a supplied JDBC URL using the documented example.
  2. The resulting connection is initiated with -u root.
  3. The operator provides root authentication material so the example can run.
  4. A malicious SQL file, unsafe request, accidental destructive statement, or credential compromise occurs while the root account is in use.
  5. The operation executes with administra ...[truncated 709 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the hardcoded -u root argument with an explicitly supplied username such as "$DB_USER".
  2. Default to a dedicated read-only account for inspection and reporting tasks.
  3. Create separate narrowly scoped accounts for data modification, schema migration, import/export, and administration.
  4. Restrict each account to the required schemas, tables, operations, and source networks.
  5. Require explicit confirmation and authorization before using an administrative account or executing destructive SQL.
  6. Prevent remote login for MySQL root where operationally possible and use audited privilege-elevation procedures for exceptional administrative work.
  7. Add transaction safeguards, backups, and change review for production modifications.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill provides INSERT, UPDATE, and DELETE examples as normal workflows without requiring confirmation, scoping limits, backups, or transaction safeguards. In an autonomous or semi-autonomous agent context, this materially increases the risk of unintended destructive changes to live data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documents executing arbitrary SQL script files without warning that the script may contain destructive statements, privilege changes, or exfiltration logic. In an agent setting, treating external SQL files as routine input is dangerous because the file content is effectively untrusted code for the database.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Bulk SQL execution and CSV import can modify or replace large volumes of data quickly, yet the skill presents them without safety checks, validation, rollback planning, or environment gating. This amplifies the blast radius of mistakes and makes mass corruption or accidental ingestion of malicious/untrusted data more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger keywords are extremely broad and cover common database terms such as MySQL, SQL execution, connection strings, table inspection, and production debugging. In an agent environment, this can cause the skill to activate in routine conversations and steer the agent toward executing powerful database operations without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The export example writes query results directly to a file on disk without warning about sensitive data handling, filesystem permissions, retention, or cleanup. This can lead to bulk exposure of database contents, especially if the output location is shared, backed up, or readable by other users/processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The database creation example performs administrative changes without warning about privilege requirements, naming collisions, governance controls, or production impact. In enterprise environments, encouraging schema creation as a routine action can bypass change-management expectations and lead to sprawl or misconfiguration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill recommends using MYSQL_PWD and storing passwords in configuration files as preferred approaches. Both can expose credentials to local users or malware via environment inspection, shell history/process environments, backups, or insecure file handling, especially on shared or production systems.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 468)May include surrounding context.

md
1. **禁止**在命令行中直接写密码(进程列表可见)
2. **使用** `MYSQL_PWD` 环境变量或配置文件
3. 生产环境**强制**使用 SSL (`--ssl-mode=REQUIRED`)
4. 配置文件权限设置为 `chmod 600 ~/.my.cnf`
5. 查询操作使用只读账号

**重要提示:** 使用 `-s -r` (`--silent --raw`) 组合确保 mysql 客户端输出纯净数据,是生成有效 JSON 的前提。

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as a Chinese-language interaction surface without any note that other languages are supported. Under the language/locale policy, a fixed language is acceptable only if the user is given a choice or the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.