Back to skill

Security audit

Sql Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill is an SQL helper, but it includes mismatched scripts, unsafe SQL text generation from unvalidated names, and undisclosed local command-history logging that users should review before installing.

Review generated SQL before running it, especially DDL, INSERT, index, migration, UPDATE, DELETE, DROP, or ALTER statements. Avoid passing sensitive SQL, customer identifiers, credentials, or private file paths to the bundled sql-generator wrapper unless you are comfortable with local history logging, and prefer staging databases, backups, transactions, and least-privileged database accounts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sql.sh:454
Finding

Unsanitized table identifiers allow injection into generated SQL

Content
View full analysis
Remediation
View remediation
&2 return 1 fi } ``` 2. Call the validator for all table names before any output is produced: ```bash validate_identifier "$table" || exit 2 ``` 3. Apply database-specific identifier quoting after validation: - MySQL and MariaDB: backticks - PostgreSQL and SQLite: double quotes 4. Do not rely on quoting alone. Reject delimiter characters, whitespace, semicolons, comments, control characters, and qualified identifiers unless explicitly supported and validated component by component. 5. Clearly label generated SQL as untrusted output that must be reviewed before execution. 6. Add regression tests using malicious identifiers containing backticks, quotes, semicolons, comment markers, newlines, and whitespace. 7. If generated SQL is ever executed automatically, use a database API that safely composes identifiers and run it through a minimally privileged database account. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:33
Finding

Command arguments are persistently recorded in a plaintext history file

Content
View full analysis
> "$DATA_DIR/history.log"; } cmd_query() { echo " Query: $*" _log "query" "${1:-}" } cmd_import() { echo " Importing: $1" _log "import" "${1:-}" } cmd_export() { echo " Exporting to: ${1:-stdout}" _log "export" "${1:-}" } cmd_transform() { echo " Transforming: $1 -> $2" _log "transform" "${1:-}" } ``` ### Technical Analysis The script creates a persistent data directory and appends command arguments to `history.log`. Query strings and import, export, or transformation paths can reveal schema information, customer identifiers, internal filenames, or other sensitive operational data. The script does not establish a restrictive umask or explicitly set the history file to mode `0600`. Its effective permissions therefore depend on the caller's environment and the permissions of a user-configurable `SQL_GENERATOR_DIR`. The logging behavior and retention period are also not disclosed in `SKILL.md`. This is not system-service persistence or a cross-session backdoor. It is application-level data retention that survives individual command executions. ### Attack Path 1. A user invokes a command with sensitive SQL content or a sensitive filesystem path. 2. `_log` appends part of that argument to `history.log`. 3. The file persists under the configured data directory after the command finishes. 4. Another local account, process, backup operator, or synchronization service with access to that directory reads or copies the history. 5. The stored query text or path information is exposed. Exploi ...[truncated 681 chars]
Remediation
View remediation
> "$DATA_DIR/history.log" ``` ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text is very broad and generic, covering any need for 'sql generator capabilities' and multiple SQL-related tasks without clear activation constraints. In an agent environment, this can cause the skill to activate in unintended contexts and generate SQL for ambiguous or risky requests, increasing the chance of unsafe database operations being suggested or executed downstream.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises SQL generation, optimization, DDL creation, mock data, and migration scripts, but provides no safety guidance about destructive statements like DELETE, UPDATE, DROP, ALTER, or bulk migrations. Without warnings or safeguards, users or downstream agents may treat generated SQL as safe to run, leading to accidental data loss, schema damage, or unsafe changes in production environments.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script presents itself as a data processing and analysis toolkit, but the listed commands largely only echo status text and append command names to a history log. This deceptive functionality can mislead users or downstream agents into believing operations such as import, export, transform, validate, and clean were actually performed, creating integrity and workflow-trust risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The help text states that the query command generates SQL based on Chinese descriptions and lists only Chinese keywords, while the file header and comments are also Chinese-centric. This indicates a language-specific constraint without any opt-in or alternative language path, which is a natural-language locale policy concern under the stated rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing instructional content only in Chinese, which can constitute a language/locale policy violation when no opt-in or alternative language option is provided. The content does not indicate that the skill is region-specific or intentionally restricted to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.