Back to skill

Security audit

Sqlx Code Review

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a normal sqlx code-review checklist, but it requires loading a separate unbundled sibling skill whose instructions were not included for review.

Review or vendor the referenced review-verification-protocol before installing. The sqlx guidance itself is ordinary, but the package should not depend on mutable instructions outside the reviewed skill package unless their content and integrity are controlled.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:25
Finding

Mandatory Loading of an Unbundled External Skill Enables Instruction Hijacking

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:25 and SKILL.md:127
Vulnerability Type: External instruction dependency
Risk Level: High

Vulnerable Code Snippets

At SKILL.md:25:

markdown
4. **Protocol** — Load and complete the [review-verification-protocol](../review-verification-protocol/SKILL.md) skill **after** gates 1–3 and **before** final severity labels. **Pass:** Protocol steps satisfied for each retained finding.

At SKILL.md:127:

markdown
Complete **Gates (evidence before severity)**, then load and follow the [review-verification-protocol](../review-verification-protocol/SKILL.md) skill before reporting any issue.

Technical Analysis

The skill twice requires the agent to load and follow instructions from ../review-verification-protocol/SKILL.md, a path outside the audited project root. The referenced file was not included in the supplied artifact and therefore could not be inspected or verified.

This creates an instruction-integrity boundary that is not controlled by the reviewed package. An attacker or untrusted package with write access to the sibling path could supply a malicious SKILL.md. Because loading that file is presented as a mandatory gate before assigning severities or reporting findings, its instructions could influence the agent's goals, suppress legitimate findings, alter risk classifications, expand the review scope, or request unauthorized actions.

The audited files contain no executable code, network retrieval, credential collection, or persistence mechanism. Exploitation therefore depends on the agent resolving the external path and an attacker being able to control or replace the referenced sibling skill.

Attack Path

  1. A user or automated agent loads this skill to perform a sqlx code review.
  2. The agent follows the mandatory protocol requirement in SKILL.md.
  3. The agent resolves ../review-verification-protocol/SKILL.md, which lies outside the audited project.
  4. A ...[truncated 1199 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the mandatory dependency on ../review-verification-protocol/SKILL.md.
  2. Vendor the complete verification protocol inside this project so it is covered by the same audit and integrity controls.
  3. If an external reference is unavoidable, treat its contents as untrusted reference data rather than authoritative instructions.
  4. Restrict references to paths inside the skill package and reject path traversal through parent-directory components such as ../.
  5. Pin and verify external skill content with a trusted cryptographic digest or signed manifest before loading it.
  6. Explicitly state that referenced content cannot modify system or user instructions, request unrelated tool operations, expand access, suppress findings, or alter the authorized review scope.
  7. Fail closed when the protocol is missing or its integrity cannot be verified, rather than searching mutable sibling directories.
  8. Include every instruction-bearing dependency in future audit artifacts so the complete effective behavior can be reviewed.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.