T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/query_sql.py:9- Finding
MySQL Read-Only Validation Permits Server-Side File Access and File Writes
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a real database-query helper, but it handles sensitive database access with under-scoped safeguards and unclear privacy/security boundaries.
Review before installing, especially for production or regulated data. Use only least-privileged read-only database accounts, avoid granting MySQL FILE privilege, prefer local or private test databases, do not store real credentials in the skill directory unless protected and gitignored, require TLS for remote database hosts, and disable OPENAI_API_KEY unless sending query text to an external LLM is acceptable.
scripts/query_sql.py:9MySQL Read-Only Validation Permits Server-Side File Access and File Writes
scripts/query_sql.py:54Database Clients Do Not Require Authenticated TLS
SKILL.md:14Plaintext Credential File Is Requested Without the Claimed Git Ignore Protection
references/config.md:55Optional Runtime Dependencies Are Unpinned and Installed Without Integrity Verification
scripts/planner_llm.py:24Natural-Language Requests Are Sent to an External LLM Without Clear Runtime Disclosure
scripts/nl_query.py:31Generated Query Plans Are Left in Temporary Storage
The skill claims guarded, read-only querying with explicit connection handling and deterministic execution, but the described behavior is inconsistent and appears to rely on minimal routing and placeholder planning rather than robust validation and execution controls. This mismatch is dangerous because users and orchestrators may trust the skill with sensitive database access under false assumptions about safety, correctness, and read-only enforcement.
The skill advertises use of scripts, environment variables, local files, and deterministic executors, but it does not declare any explicit tool scope such as allowed tools or permissions. That creates an authorization ambiguity where an agent may invoke shell, read files, or access environment data more broadly than intended, increasing the risk of unintended secret exposure or unsafe execution paths.
The skill instructs users to provide usernames, passwords, and local connection profiles, but it does not include explicit warnings or handling guidance for sensitive credentials. In practice, this can lead users to paste secrets into prompts, logs, or versioned files, causing credential leakage and unauthorized database access.
The documentation explicitly tells users to copy a template and edit a local JSON file with real database credentials, but it does not warn about secret handling, file permissions, accidental commits, or safer alternatives. In a skill designed to connect to MySQL, Redis, and MongoDB, this increases the likelihood of credential exposure through source control, backups, logs, or shared workspaces.
The examples demonstrate direct querying of MySQL, Redis, and MongoDB using realistic profile names and live-style data access patterns, but they provide no warning about production use, sensitive records, or least-privilege access. In a skill specifically designed for natural-language database querying, this omission can normalize running ad hoc reads against real systems and increase the chance of exposing customer data, secrets, or operational metadata.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run(cmd: list[str]):
proc = subprocess.run(cmd, capture_output=True, text=True)
if proc.returncode != 0:
sys.stderr.write(proc.stderr)
raise SystemExit(proc.returncode)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run(cmd: list[str]) -> tuple[int, str, str]:
p = subprocess.run(cmd, capture_output=True, text=True)
return p.returncode, p.stdout, p.stderr
The script forwards raw natural-language input to planner_llm.py, which likely sends or processes that text in another component, without any explicit disclosure or consent mechanism. In a tool that may be used against local databases and may receive sensitive operational questions, this can expose secrets, internal schema details, or regulated data through downstream logging, model providers, or telemetry.
The planner transmits natural-language user requests to an external OpenAI API, which expands the skill's trust boundary beyond local middleware querying. Because user prompts may contain sensitive operational data, database names, keys, or query targets, this creates an undisclosed data exfiltration/privacy risk that is not inherent to a local read-only query tool.
The code reads an environment API credential and uses it to perform network-backed model inference, introducing external connectivity and secret-dependent behavior not justified by the core middleware-query purpose. In a skill advertised for local database/middleware access, this increases the attack surface and can violate operator expectations about where data is processed.
User request text is sent directly to a third-party LLM service without any warning, consent, or in-file disclosure mechanism. Since natural-language database requests often include sensitive business data or identifiers, this can leak confidential information even if the eventual database operations are read-only.
The script accepts Mongo credentials and connection parameters from environment variables in addition to the declared profile/explicit connection inputs. In an agent setting, this can silently redirect queries to unintended databases or use ambient secrets without clear user consent, undermining the stated explicit-connection-configuration boundary and increasing the risk of accidental secret use or data access.
This code retrieves credentials and immediately establishes a live network connection to MongoDB without any user-facing disclosure in the executor itself. In a natural-language querying skill, that makes it easier for users or higher-level agent components to trigger access to real data stores without clear visibility that stored or ambient credentials will be used.
The script silently accepts Redis connection parameters from environment variables even though the skill is described as using explicit connection configuration. That broadens the data-access capability beyond what a caller may expect, and in an agent setting can cause the tool to connect to unintended Redis instances using ambient credentials present in the runtime environment.
The tool returns raw Redis query results directly as JSON, which can expose sensitive values, secrets, session data, or internal application state to the caller. Although mask_sensitive may reduce some exposure, there is no explicit user-facing warning, confirmation, or result minimization despite this being a database-content exfiltration path.
This code reads sensitive connection details, including MYSQL_PASSWORD, from environment variables and profile configuration, but the file provides no confirmation prompt, warning comment, docstring, or user-facing message explaining that credentials will be accessed. For a code file, accessing sensitive environment variables without any disclosure matches the missing user warnings criterion.
The router's MySQL branch ignores the user's natural-language request and always emits SELECT * FROM users ORDER BY id DESC LIMIT .... In a read-only database skill, this can cause unauthorized or unintended disclosure of data from a likely sensitive table, because unrelated prompts are silently mapped to a broad users-table query rather than a minimally scoped query derived from user intent.
The output format requires a 'Short interpretation in Chinese,' which imposes a specific language regardless of user preference. This is a natural-language policy concern because the skill does not provide opt-in, fallback, or language selection.
The natural-language examples are written in Chinese (查一下 redis 里..., 查mongo ... 最近20条) and the file does not indicate that Chinese input is optional or that the skill is intentionally limited to a Chinese-speaking context. This can conflict with language or locale policy expectations when no user opt-in or justification is provided.
No suspicious patterns detected.