Back to skill

Security audit

CRUD Code Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent CRUD generator, but its templates can generate under-scoped data access code and destructive SQL examples that need review before use.

Use this skill only with explicit target paths and review all generated code before merging or deploying it. Add tenant or ownership checks to generated read, update, delete, list, count, and export operations, derive operatorId from the authenticated user rather than client input, and treat generated DROP TABLE SQL as development-only unless deliberately approved.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/java-templates.md:422
Finding

Generated CRUD Operations Do Not Enforce Tenant-Level Record Isolation

Content
View full analysis
pageByQueryParam(XxxYyyQueryParam query, Pageable pageable) { IPage queryPage = PageUtil.toMybatisPage(pageable); IPage page = xxxYyyMapper.selectPage(queryPage, QueryHelpMybatisPlus.getPredicate(query)); return xxxYyyConverter.convertPage(page); } @Override public List listByQueryParam(XxxYyyQueryParam query) { return xxxYyyConverter.toDto(xxxYyyMapper.selectList(QueryHelpMybatisPlus.getPredicate(query, "id", false))); } @Override public long countByQueryParam(XxxYyyQueryParam query) { return xxxYyyMapper.selectCount(QueryHelpMybatisPlus.getPredicate(query)); } @Override // @Cacheable(key = "'id:' + #p0") public XxxYyyDTO getById(Long id) { return xxxYyyConverter.toDto(xxxYyyMapper.selectById(id)); } @Override // @CacheEvict(allEntries = true) @Transactional(rollbackFor = Exception.class) public void insert(XxxYyyDTO res) { XxxYyy entity = xxxYyyConverter.toEntity(res); xxxYyyMapper.insert(entity); res.setId(entity.getId()); } @Override // @CacheEvict(allEntries = true) @Transactional(rollbackFor = Exception.class) public void updateById(XxxYyyDTO res) { XxxYyy entity = xxxYyyConverter.toEntity(res); xxxYyyMapper.updateById(entity); } @Override // @CacheEvict(allEntries = true) @Transactional(rollbackFor = Exception.class) public void removeByIds(Set ids) { xxxYyyMapper.deleteBatchIds(ids); } ``` ### Technical Analysis The skill generates CRUD service methods that operate on records without consistently applying an authenticated tenant or operator constraint. The template explicitly recognizes `operator_id` as a tenant field elsewhere in the file, but the affected methods rely on either: - Query para ...[truncated 3102 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises automatic project scanning, code generation, SQL generation, and build/runtime validation, but it does not clearly warn that these actions may modify files, inspect repository structure, or execute environment-affecting commands such as mvn clean package and npm run dev. In practice, users may invoke the skill without understanding that it can alter the codebase or consume local tooling and resources, creating integrity and operational risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad and generic, such as requests to generate CRUD or data management code, without clear repository, framework, or confirmation boundaries. In an agent setting, this can cause unintended activation on loosely related prompts and lead the skill to scaffold or modify the wrong project areas, increasing the chance of unsafe or unexpected codebase changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template includes a destructive DROP TABLE IF EXISTS statement and instructs users to directly copy original DDL without adding any safety guardrails or warnings. In a CRUD code generation skill, this increases the chance that generated migration or deployment SQL could be run in the wrong environment and cause irreversible data loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README presents the skill's title, functionality, and usage instructions in Chinese, which can implicitly force a specific language experience on users without opt-in. There is no indication that the skill is intentionally region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains natural-language guidance that assumes Chinese as the required language for generated table text and labels. Because the file does not offer an opt-in or document a justified locale restriction, it may violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.