Back to skill

Security audit

Database Helper Pro

Security checks for vulnerabilities and agentic risk

Overview

This database helper is not malicious, but it includes write/delete database operations and unsafe query-building patterns without enough guardrails.

Review before installing or using this skill on real databases. Treat it as a prototype helper for trusted local data only unless it is updated to validate identifiers, restrict raw SQL fragments, require explicit confirmation for writes/deletes/schema changes, and clarify that the provided implementation is SQLite-only.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:34
Finding

SQL Injection Through Unvalidated Identifiers and Query Fragments

Content
View full analysis
'SQLBuilder': cols = ", ".join(columns) if columns else "*" self._query = f"SELECT {cols} FROM {self.table}" return self def where(self, condition: str, *params) -> 'SQLBuilder': self._query += f" WHERE {condition}" self._params.extend(params) return self def order_by(self, column: str, desc: bool = False) -> 'SQLBuilder': direction = "DESC" if desc else "ASC" self._query += f" ORDER BY {column} {direction}" return self def limit(self, n: int) -> 'SQLBuilder': self._query += f" LIMIT {n}" return self def join(self, table: str, on: str) -> 'SQLBuilder': self._query += f" JOIN {table} ON {on}" return self def insert(self, data: dict) -> 'SQLBuilder': cols = ", ".join(data.keys()) placeholders = ", ".join(["?"] * len(data)) self._query = f"INSERT INTO {self.table} ({cols}) VALUES ({placeholders})" self._params = list(data.values()) return self def update(self, data: dict) -> 'SQLBuilder': set_clause = ", ".join(f"{k} = ?" for k in data.keys()) self._query = f"UPDATE {self.table} SET {set_clause}" self._params = list(data.values()) return self def delete(self) -> 'SQLBuilder': self._query = f"DELETE FROM {self.table}" return self ``` ```python def create_table(self, name: str, columns: Dict[str, str], primary_key: str = "id") -> str: cols = [f"{primary_key} INTEGER PRIMARY KEY AUTOINCREMENT"] for col_name, col_type in columns.items(): cols.append(f"{col_name} {col_type}") query = f"CREATE TABLE IF NOT EXISTS {name} ({', '.join(cols)})" self.execute(query) return query ``` ```python for table in tables: table_name = table["name"] columns = self.execute(f"PRAGMA table_info({table_name})") ...[truncated 3494 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:167
Finding

Python Code Injection in Generated ORM Templates

Content
View full analysis
str: """生成ORM模型模板""" fields = [] for col, dtype in columns.items(): py_type = "str" if "CHAR" in dtype.upper() or "TEXT" in dtype.upper() else "int" if "INT" in dtype.upper() else "float" fields.append(f" {col}: {py_type}") return f""" from dataclasses import dataclass from typing import Optional @dataclass class {table_name.title()}: {chr(10).join(fields)} @classmethod def from_row(cls, row: dict) -> '{table_name.title()}': return cls(**{{k: v for k, v in row.items() if k in cls.__dataclass_fields__}}) def to_dict(self) -> dict: import dataclasses return dataclasses.asdict(self) """ ``` ### Technical Analysis The method generates executable Python source by directly inserting `table_name` and column names into a formatted string. These values are not checked to ensure that they are valid, safe Python identifiers. A malicious name can contain line breaks, assignments, function calls, decorators, or other Python syntax. This content becomes part of the generated module or class body. If the generated template is subsequently saved and imported, passed to `exec()`, or otherwise executed, injected expressions can run with the privileges of the consuming Python process. The type-selection logic does not mitigate this issue because the attacker-controlled column name is inserted before the generated type annotation. Calling `.title()` on the table name also does not provide syntactic validation or escaping. ### Attack Path 1. An attacker controls or influences a table or column name supplied to `orm_template()`, potentially through an imported schema or application request. 2. The attacker includes newline characters and valid Pyth ...[truncated 1183 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description explicitly says the skill supports SQLite, MySQL, and PostgreSQL. In the provided implementation, the only database backend imported or used is Python's sqlite3 module, and all connection and schema inspection logic is SQLite-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The listed trigger phrase set includes very broad everyday terms such as "SQL", "database", and "查询" without any scope limits, exclusions, or context constraints. In a markdown skill description, this can cause the skill to activate for many ordinary conversations about databases or queries rather than clear intentional invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill exposes destructive capabilities such as DELETE, CREATE TABLE, UPDATE, and CSV import/export without any documented warning, guardrail, or confirmation requirement. In an agent setting, this increases the risk of accidental or unauthorized data destruction or schema changes because users may invoke powerful operations without understanding the consequences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The description and headings prominently use Chinese for core instructions and labels, and no language-selection option or justification for a Chinese-only locale is provided. This may violate language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The feature list includes '连接池管理' (connection pool management), which implies pooled or managed multiple connections. The code only stores a single sqlite3 connection in self.conn and provides simple connect/close methods, so the documentation overstates the implemented behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.