Back to skill

Security audit

database-admin

Security checks for vulnerabilities and agentic risk

Overview

This database-admin skill is coherent in purpose, but it publishes a real-looking PostgreSQL admin credential and includes high-impact database/file operations without adequate safeguards.

Do not install this skill as published unless you own the referenced roadflow database and have already rotated the exposed password. Treat the credential as compromised, replace hardcoded secrets with environment variables or a secret manager, use least-privilege DB roles, add confirmation/dry-run controls for destructive actions, and validate or safely quote all SQL identifiers before using these scripts on any real database.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
query_kaoqin_forms.js:4
Finding

Hard-Coded PostgreSQL Administrator Credentials

Content
View full analysis
Remediation
View remediation
`. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/schema_migrate.js:25
Finding

SQL Injection Through Dynamically Interpolated Identifiers, Values, and Schema Operations

Content
View full analysis
c.name.toUpperCase() === 'ID'); let sql = `CREATE TABLE IF NOT EXISTS ${tableName} (\n`; const colDefs = columns.map((col, idx) => { let def = `${col.name}${col.type}`; if (idx === 0 && !pkColumn) { def += ' PRIMARY KEY'; } else if (pkColumn && col.name.toUpperCase() !== 'ID') { def += ` DEFAULT ${col.type}::${col.type}`; } return `${def}${col.index ? ` [索引:${col.index}]` : ''}`; }).join(',' + '\n'); const idxDefs = columns.filter(c => c.index).map(col => `CREATE INDEX IF NOT EXISTS ${col.name}_idx ON ${tableName} (${col.index || col.name});` ).join('\n'); return `${sql}${colDefs}\n);${idxDefs}`; } ``` `scripts/create_table.js:88-94`: ```js const values = batch.map(r => Object.keys(r).map(k => `'${r[k]}'`).join(', ') ); const sql = `INSERT INTO ${tableName} (VALUES ${values.join('), (')})`; await pool.query(sql); ``` `scripts/query_helper.js:38-42`: ```js function generateStatsQuery(table, fields = [], where = {}, groupBy = []) { const conditions = Object.entries(where).map(([k, v]) => `WHERE ${k} = '${v}'` ).join(' AND '); ``` `scripts/schema_migrate.js:25-65`: ``` ...[truncated 5173 chars]
Remediation
View remediation
$1::jsonb LIMIT 100', [JSON.stringify(searchObject)] ); ``` 6. Run read-only query tools using a database role that cannot modify schemas or data. 7. Treat raw query-analysis and benchmark functions as privileged administrative capabilities. Require explicit authorization and reject non-`SELECT` input where arbitrary statements are unnecessary. 8. Add transaction boundaries to bulk operations and ensure rollback occurs through a client checked out from the pool, rather than issuing transaction statements through unrelated pooled connections. 9. Add security tests covering quote termination, semicolons, SQL comments, malicious identifiers, unsafe defaults, and injected migration expressions. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backup_restore.js:184
Finding

Unrestricted Backup Paths and Overbroad Backup Cleanup

Content
View full analysis
daysToKeep) { fs.unlinkSync(path.join(backupDir, file)); deletedCount++; console.log(`🗑️ 删除旧备份:${file} (已存在 ${ageDays} 天)`); } } ``` ### Technical Analysis Backup destinations and source paths are accepted without canonicalization, containment enforcement, symlink checks, or file-type validation. The database name is also concatenated into the output filename. A caller able to control `options.outputDir`, `databaseName`, `backupPath`, or `BACKUP_DIR` can redirect operations outside the intended backup area. `writeFileSync()` follows an existing symboli ...[truncated 2720 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (49)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill documentation exposes a concrete PostgreSQL host, port, username, password, and target database. This is a real secret exposure that could allow unauthorized parties to connect directly to the database and perform data theft, tampering, or destructive administrative actions, especially because the skill is explicitly for database administration.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script fetches and prints complete records from attendance/HR-related forms, which are likely to contain sensitive personnel, leave, attendance, or payroll information. Dumping full rows to console creates a straightforward data-exfiltration path via logs, terminals, CI output, or shared environments, especially given the HR context increases sensitivity.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains hardcoded PostgreSQL connection details, including a plaintext password and internal host information. Anyone with access to the source can reuse these credentials to connect to the database, potentially leading to unauthorized access, data theft, or modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises destructive operations such as DROP TABLE, DROP INDEX, TRUNCATE, and restore-related actions without any safeguards, confirmation requirements, scoping limits, or warnings. In a database-admin skill, these capabilities are contextually relevant, but presenting them without safety controls increases the risk of accidental or unauthorized destructive execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains hardcoded PostgreSQL credentials, including host, username, and password. Embedded secrets are highly dangerous because anyone with access to the code can reuse them to connect to the database, enabling unauthorized access, data theft, or tampering far beyond this script's intended behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The comment at L51 says the code is obtaining the maximum ID '用于生成新表单' (for generating a new form), while the surrounding script otherwise presents itself as a query-only tool for attendance/personnel forms. This introduces intent divergence because the script's documented/query-focused behavior is contradicted by preparatory logic for creating new forms.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script retrieves and prints a full row from the rf_form table to the console, which can expose sensitive or regulated data to logs, terminals, or CI output. Because this appears to be a database inspection utility with no redaction, access control, or warning, it increases the risk of unintended data disclosure if run in shared environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The backup/restore section shows restore and cleanup operations but does not warn that these actions can overwrite data, import untrusted SQL, or delete backups irreversibly. In an admin-oriented skill, omission of such safeguards can cause destructive operator mistakes and increases the chance of unsafe use in production.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The schema migration examples perform production-impacting changes such as add-column, modify-type, add-index, and data migration without warning about locks, downtime, rollback planning, or backup requirements. In database administration context, these omissions can directly lead to availability issues or accidental data corruption when copied into live systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The production backup example includes creation of database dumps, compression, and remote upload instructions without warning that backups contain sensitive data and may expose credentials or regulated information if mishandled. Because this is framed as a production workflow, the lack of privacy, encryption, and access-control guidance makes misuse materially more dangerous.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · references/USAGE_GUIDE.md (reported line 196)May include surrounding context.

md
gzip "$BACKUP_DIR/full_$DATE.sql"

# 4. 上传到远程存储(s3/cos/gcs等)
# aws s3 cp local_file s3://bucket/...

# 5. 清理旧备份
node scripts/backup_restore.js --cleanup --days 30

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cleanupOldBackups function permanently removes files with fs.unlinkSync based on age. Although it logs each deletion after the fact, there is no confirmation prompt or upfront warning in the CLI help text that invoking cleanup will delete files from the backup directory.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module header says this is a '表创建工具' used to quickly create database table structures, and its examples only show table creation. However, the code later defines insertData and the CLI help advertises inserting records into existing tables, which is a materially different write capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The createTable function executes a CREATE TABLE statement against the configured database, which changes persistent system state. Although success and error logs are present, there is no prior user-facing warning, confirmation, or explanatory comment disclosing that the script will alter the target database when run.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The insertData function performs batch INSERT operations that persist user-supplied records to the database. The code logs progress after insertion, but it does not provide a clear warning or confirmation beforehand that running the command will write data to the configured database.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file contains natural-language instructions and CLI help text that force a specific language for users. Under the policy, a skill should not impose a language or locale unless it offers opt-in or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation at L19-L21 says the function performs bulk insertion using COPY FROM STDIN for maximum efficiency. However, the implementation at L47-L49 builds a COPY SQL string and passes an array to pool.query rather than using a streaming COPY STDIN mechanism, so the documented intent and actual behavior materially diverge.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The inline comment explicitly says the code is using the COPY protocol for high-performance bulk insertion. In practice, the code only constructs a COPY statement and calls pool.query with an array, which does not match the documented protocol usage and overstates what the code is doing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

All natural-language descriptions, logs, and CLI help are written in Chinese, with no indication that the user can choose another language. This can violate language/locale policy when a skill imposes a specific language without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The function is documented as extracting a specific field from the JSONB column provided by the caller, but the SQL uses data->> instead of the jsonbColumn parameter. This is an intent-code mismatch because the documentation and signature imply configurable column selection while the code only operates on a fixed column.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The comment and function signature indicate that the selected JSONB column will be indexed, yet the generated SQL ignores jsonbColumn and creates a GIN index on data. This actively contradicts the stated behavior and can mislead users about what data is being optimized.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function is presented as validating whichever JSONB column is passed in, but the SQL ignores jsonbColumn and checks data instead. This is a direct contradiction between the documented intent and actual behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function signature and comment suggest general statistics over a chosen JSONB field, but the SQL ignores jsonbColumn and counts only data->>'key'. This contradicts the apparent intent of the API and CLI-facing behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function is documented and parameterized as if the caller can choose the related table, yet the SQL performs LEFT JOIN link_table regardless of the linkTable argument. This is an active contradiction between declared intent and real behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation and function signature imply conversion from textColumn into jsonbColumn, but the CASE expression and parser both reference data rather than the caller-supplied source column. This means the implemented behavior diverges from the stated intent and may update rows based on unrelated data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.