Back to skill

Security audit

Azuredatastudio

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it is marketed like Azure Data Studio while mostly providing stub/local scripts that log command history.

Review this before installing if you expected the real Azure Data Studio or Microsoft-backed functionality. Treat it as a local demo/stub CLI, avoid passing secrets or sensitive SQL as command arguments, and be aware that command history is saved under the configured azuredatastudio data directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description suggests a functional Azure Data Studio-related tool for data management and development with cloud connectivity. The supplied code does not implement such capabilities. It is only a lightweight shell script that echoes help, version/info, status, and a TODO placeholder for run. This is a material description-behavior mismatch because the primary purpose and capabilities described are not actually present in the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents the skill as Azure Data Studio, a real data management/development tool with cloud/database connectivity. The supplied code is instead a lightweight bash script with stub commands that print messages, inspect a local log file, and record usage history under a local directory. Its primary purpose and capabilities materially differ from the declared description: it neither connects to Azure nor performs substantive database or development-tool actions. While the script does operate in a broad 'data toolkit' space, the specific product identity and expected capabilities are not accurately represented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Persistently logging command history to a local file can expose sensitive queries, filenames, identifiers, or other operational data without adequate user warning. In a data-tool context, users may enter secrets, proprietary query text, or sensitive record references, so undisclosed retention increases privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest frames the skill as Azure Data Studio-related and specifically mentions connectivity to cloud/data platforms, which implies database or service interaction. In contrast, the script only echoes messages, reads local log files, and writes command history under a local data directory, so its implemented behavior does not match the stated product purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script logs user-supplied command arguments directly to a persistent history file under the user's data directory without warning or consent. If users pass sensitive values such as query text, file paths, tokens, identifiers, or secrets via command-line arguments, those values may be retained on disk and later exposed to other local processes, backups, or support artifacts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The inline description and help text present the tool as performing substantive data operations. However, commands such as import, export, transform, validate, and clean do not manipulate data at all; they only echo messages and append to a history log, which contradicts the documented intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.