Back to skill

Security audit

SQL Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This SQL helper is mostly what it claims to be, but its database migration and restore examples can overwrite or corrupt real data without enough safety guardrails.

Review the migration and restore snippets carefully before installing or using this skill. Treat its examples as templates that need hardening: verify the target database, back up first, avoid running restore commands against production names, validate migration filenames, and prefer transactional or tool-managed migrations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:298
Finding

SQL Injection and Unsafe Filename Handling in Migration Script

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi already=$( psql "$DB_URL" -v version="$version" -tAc \ "SELECT 1 FROM schema_migrations WHERE version = :'version';" ) if [ "$already" = "1" ]; then printf 'SKIP: %s (already applied)\n' "$version" continue fi psql "$DB_URL" -v ON_ERROR_STOP=1 -f "$file" && psql "$DB_URL" -v ON_ERROR_STOP=1 -v version="$version" -c \ "INSERT INTO schema_migrations (version) VALUES (:'version');" done ``` If ordering is required, generate a safely sorted, null-delimited list rather than relying on `ls` and shell word splitting. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill provides migration, backup, restore, and cleanup commands that can alter or overwrite database state, including examples like pg_restore --clean --if-exists and direct restore redirection into live databases, without prominent warnings about destructive effects, environment targeting, transaction safety, or rollback planning. In a tool explicitly meant to operate on real databases, omission of safety guardrails increases the chance that an agent or user runs these commands against production or the wrong target, causing data loss or service disruption.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.