Back to skill

Security audit

Middleware Query

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real database-query helper, but it handles sensitive database access with under-scoped safeguards and unclear privacy/security boundaries.

Review before installing, especially for production or regulated data. Use only least-privileged read-only database accounts, avoid granting MySQL FILE privilege, prefer local or private test databases, do not store real credentials in the skill directory unless protected and gitignored, require TLS for remote database hosts, and disable OPENAI_API_KEY unless sending query text to an external LLM is acceptable.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/query_sql.py:9
Finding

MySQL Read-Only Validation Permits Server-Side File Access and File Writes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/query_sql.py:54
Finding

Database Clients Do Not Require Authenticated TLS

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:14
Finding

Plaintext Credential File Is Requested Without the Claimed Git Ignore Protection

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/config.md:55
Finding

Optional Runtime Dependencies Are Unpinned and Installed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/planner_llm.py:24
Finding

Natural-Language Requests Are Sent to an External LLM Without Clear Runtime Disclosure

Content
View full analysis
Optional[Dict[str, Any]]: api_key = os.getenv("OPENAI_API_KEY") if not api_key: return None try: from openai import OpenAI # type: ignore client = OpenAI(api_key=api_key) resp = client.responses.create( model=model, input=[ {"role": "system", "content": SYSTEM_PROMPT}, {"role": "user", "content": prompt}, ], temperature=0, ) ``` The prompt contains the complete request and profile names: ```python base_prompt = ( f"User request: {text}\n" f"Default profiles: mysql={mysql_profile}, redis={redis_profile}, mongo={mongo_profile}\n" "Return a single JSON plan." ) ``` ### Technical Analysis When `OPENAI_API_KEY` is present, the planner sends the complete natural-language request and configured profile identifiers to OpenAI. Users may place confidential identifiers, table names, key names, customer identifiers, query literals, or business-sensitive conditions in that text. The reviewed code does not send query results or connection passwords to OpenAI. However, it also performs no redaction, classification, or consent check before sending the request. The configuration reference describes the API key as enabling the planner but does not provide a clear runtime warning about exactly what content leaves the local environment. The external call is legitimate planner functionality, not remote payload execution. The security issue is insufficient disclosure and data-minimization control. ### Attack Path 1. A user configures `OPENAI_API_KEY`. 2. The user invokes `nl_query.py` with a request containing sensitive names, identifiers, or litera ...[truncated 664 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/nl_query.py:31
Finding

Generated Query Plans Are Left in Temporary Storage

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims guarded, read-only querying with explicit connection handling and deterministic execution, but the described behavior is inconsistent and appears to rely on minimal routing and placeholder planning rather than robust validation and execution controls. This mismatch is dangerous because users and orchestrators may trust the skill with sensitive database access under false assumptions about safety, correctness, and read-only enforcement.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises use of scripts, environment variables, local files, and deterministic executors, but it does not declare any explicit tool scope such as allowed tools or permissions. That creates an authorization ambiguity where an agent may invoke shell, read files, or access environment data more broadly than intended, increasing the risk of unintended secret exposure or unsafe execution paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs users to provide usernames, passwords, and local connection profiles, but it does not include explicit warnings or handling guidance for sensitive credentials. In practice, this can lead users to paste secrets into prompts, logs, or versioned files, causing credential leakage and unauthorized database access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly tells users to copy a template and edit a local JSON file with real database credentials, but it does not warn about secret handling, file permissions, accidental commits, or safer alternatives. In a skill designed to connect to MySQL, Redis, and MongoDB, this increases the likelihood of credential exposure through source control, backups, logs, or shared workspaces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The examples demonstrate direct querying of MySQL, Redis, and MongoDB using realistic profile names and live-style data access patterns, but they provide no warning about production use, sensitive records, or least-privilege access. In a skill specifically designed for natural-language database querying, this omission can normalize running ad hoc reads against real systems and increase the chance of exposing customer data, secrets, or operational metadata.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/execute_plan.py (reported line 14)May include surrounding context.

python
def run(cmd: list[str]):
    proc = subprocess.run(cmd, capture_output=True, text=True)
    if proc.returncode != 0:
        sys.stderr.write(proc.stderr)
        raise SystemExit(proc.returncode)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/nl_query.py (reported line 17)May include surrounding context.

python
def run(cmd: list[str]) -> tuple[int, str, str]:
    p = subprocess.run(cmd, capture_output=True, text=True)
    return p.returncode, p.stdout, p.stderr

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script forwards raw natural-language input to planner_llm.py, which likely sends or processes that text in another component, without any explicit disclosure or consent mechanism. In a tool that may be used against local databases and may receive sensitive operational questions, this can expose secrets, internal schema details, or regulated data through downstream logging, model providers, or telemetry.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The planner transmits natural-language user requests to an external OpenAI API, which expands the skill's trust boundary beyond local middleware querying. Because user prompts may contain sensitive operational data, database names, keys, or query targets, this creates an undisclosed data exfiltration/privacy risk that is not inherent to a local read-only query tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code reads an environment API credential and uses it to perform network-backed model inference, introducing external connectivity and secret-dependent behavior not justified by the core middleware-query purpose. In a skill advertised for local database/middleware access, this increases the attack surface and can violate operator expectations about where data is processed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

User request text is sent directly to a third-party LLM service without any warning, consent, or in-file disclosure mechanism. Since natural-language database requests often include sensitive business data or identifiers, this can leak confidential information even if the eventual database operations are read-only.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script accepts Mongo credentials and connection parameters from environment variables in addition to the declared profile/explicit connection inputs. In an agent setting, this can silently redirect queries to unintended databases or use ambient secrets without clear user consent, undermining the stated explicit-connection-configuration boundary and increasing the risk of accidental secret use or data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code retrieves credentials and immediately establishes a live network connection to MongoDB without any user-facing disclosure in the executor itself. In a natural-language querying skill, that makes it easier for users or higher-level agent components to trigger access to real data stores without clear visibility that stored or ambient credentials will be used.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script silently accepts Redis connection parameters from environment variables even though the skill is described as using explicit connection configuration. That broadens the data-access capability beyond what a caller may expect, and in an agent setting can cause the tool to connect to unintended Redis instances using ambient credentials present in the runtime environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The tool returns raw Redis query results directly as JSON, which can expose sensitive values, secrets, session data, or internal application state to the caller. Although mask_sensitive may reduce some exposure, there is no explicit user-facing warning, confirmation, or result minimization despite this being a database-content exfiltration path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code reads sensitive connection details, including MYSQL_PASSWORD, from environment variables and profile configuration, but the file provides no confirmation prompt, warning comment, docstring, or user-facing message explaining that credentials will be accessed. For a code file, accessing sensitive environment variables without any disclosure matches the missing user warnings criterion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The router's MySQL branch ignores the user's natural-language request and always emits SELECT * FROM users ORDER BY id DESC LIMIT .... In a read-only database skill, this can cause unauthorized or unintended disclosure of data from a likely sensitive table, because unrelated prompts are silently mapped to a broad users-table query rather than a minimally scoped query derived from user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The output format requires a 'Short interpretation in Chinese,' which imposes a specific language regardless of user preference. This is a natural-language policy concern because the skill does not provide opt-in, fallback, or language selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language examples are written in Chinese (查一下 redis 里..., 查mongo ... 最近20条) and the file does not indicate that Chinese input is optional or that the skill is intentionally limited to a Chinese-speaking context. This can conflict with language or locale policy expectations when no user opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.