Back to skill

Security audit

huawei-cloud-doris-sql-check

Security checks for vulnerabilities and agentic risk

Overview

The skill is a local Doris SQL checker, but its documented command examples can let untrusted SQL trigger local shell execution if followed literally.

Review before installing. Use this only if the agent invokes the Python checker through direct imports, argv arrays, stdin, or a securely handled file; do not paste untrusted SQL into shell command strings. Treat results as advisory, and require explicit read-only opt-in before any future live database or MCP-backed performance checks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:78
Finding

Shell Command Injection Through Documented SQL Invocation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 78, 127, 273, and 307
Vulnerability Type: Shell command injection
Risk Level: High

Vulnerable snippets:

bash
python ~/.cac/skills/huawei-cloud-doris-sql-check/scripts/doris_sql_tokenizer.py "<sql_text>"
bash
python ~/.cac/skills/huawei-cloud-doris-sql-check/scripts/doris_sql_parser.py "<sql_text>"
bash
python ~/.cac/skills/huawei-cloud-doris-sql-check/scripts/doris_sql_checker.py "<sql_text>" all
bash
python ~/.cac/skills/huawei-cloud-doris-sql-check/scripts/doris_sql_checker.py "<sql_text>" [syntax|spec|all]

Technical Analysis

The Skill instructs the agent to insert SQL text directly into double-quoted shell command templates. SQL is intended to be treated only as data, but legitimate SQL can contain double quotes, backticks, dollar signs, command substitutions, semicolons, and other shell metacharacters.

If an agent constructs a command string from these templates and invokes it through a shell, shell parsing and expansion occur before the Python checker receives sys.argv. Consequently, the tokenizer and parser cannot neutralize the injected syntax.

For example, attacker-supplied SQL containing a construct such as:

sql
SELECT "$(malicious_command)";

can cause malicious_command to execute through shell command substitution before the Python process starts. The precise payload and quoting requirements depend on how the invoking agent constructs the final shell command.

The Python implementation itself does not spawn subprocesses or evaluate SQL as code. The vulnerability is in the documented invocation workflow rather than in SQL tokenization.

Attack Path

  1. An attacker supplies SQL for review through a user request, shared artifact, issue, or another input source processed by the agent.
  2. The SQL contains shell metacharacters or command substitution syntax.
  3. Following SKILL.md, the agent replaces <sql_text> with the supp ...[truncated 969 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not interpolate SQL into a shell command string.
  2. Prefer importing and calling the checker directly:
python
from doris_sql_checker import check_sql_markdown

report = check_sql_markdown(sql_text, "all")
print(report)
  1. If a separate process is required, use a non-shell argument-vector API:
python
subprocess.run(
    [
        sys.executable,
        checker_path,
        sql_text,
        "all",
    ],
    shell=False,
    check=True,
)
  1. For large or complex SQL, accept the content through standard input or a securely handled input file while still launching the process with an argument list.
  2. Remove the vulnerable shell templates from SKILL.md or replace them with an invocation method that cannot cause shell interpretation.
  3. Explicitly instruct agents and integrators not to use shell=True, shell command strings, or textual command interpolation for SQL input.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is a stronger form of the same issue: the skill reportedly lacks the core parsing and validation behavior it claims to perform. When a checking skill claims to audit SQL but performs little or no real validation, users may rely on it for change review, security checks, or deployment gating, allowing unsafe SQL to pass undetected.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is a stronger form of the same issue: the skill reportedly lacks the core parsing and validation behavior it claims to perform. When a checking skill claims to audit SQL but performs little or no real validation, users may rely on it for change review, security checks, or deployment gating, allowing unsafe SQL to pass undetected.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 276)May include surrounding context.

md
[doris_sql_checker.py](scripts/doris_sql_checker.py)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

md
[doris_sql_parser.py](scripts/doris_sql_parser.py)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 331)May include surrounding context.

md
| [Specification Rules](rules/spec_rules.yaml) | 40 specification check rule definitions |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 333)May include surrounding context.

md
| [Keywords](rules/keywords.py) | 504 Doris SQL keyword definitions (from DorisLexer.g4) |

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/doris_sql_parser.py (reported line 483)May include surrounding context.

python
)

    def _parse_delete(self):
        """Parse DELETE statement"""
        self._expect_keyword("DELETE")
        self._expect_keyword("FROM")
        table = self._consume_qualified_name()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest explicitly defines trigger phrases primarily in Chinese ("触发词") while the rest of the skill content is largely in English, and it does not state that users may invoke the skill in other languages. This can create a language/locale constraint without clear user opt-in, which matches the policy-violation category for forced language behavior.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
## Check Modes

| Mode       | Dependency | Description                                                                                          |
| ---------- | ---------- | ---------------------------------------------------------------------------------------------------- |
| **syntax** | None       | Syntax check: keyword validity, statement structure, clause completeness, Doris syntax compatibility |
| **spec**   | None       | Specification check: object design standards, data operation standards, naming conventions           |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
**Syntax Check Rules (34 rules)**:

| Rule ID | Name                                 | Level   | Description                                                                                                 |
| ------- | ------------------------------------ | ------- | ----------------------------------------------------------------------------------------------------------- |
| SYN-ERR | Lexical Error                        | ERROR   | Unrecognized characters in SQL text                                                                         |
| SYN001  | Invalid Keyword                      | ERROR   | Keyword not supported by Doris (not in 504-keyword list)                                                    |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

md
| SYN008  | EXPLAIN planType Syntax Error        | ERROR   | Invalid EXPLAIN plan type (PARSED/ANALYZED/REWRITTEN/LOGICAL/OPTIMIZED/PHYSICAL/SHAPE/MEMO/DISTRIBUTED/ALL) |
| SYN009  | KEY Model Syntax Error               | ERROR   | Invalid data model (DUPLICATE/AGGREGATE/UNIQUE KEY)                                                         |
| SYN010  | PROPERTIES Syntax Error              | ERROR   | Invalid PROPERTIES clause structure                                                                         |
| SYN011  | ENGINE Syntax Error                  | ERROR   | Invalid ENGINE clause                                                                                       |
| SYN012  | INSERT OVERWRITE Syntax Error        | ERROR   | Invalid INSERT OVERWRITE TABLE structure                                                                    |
| SYN013  | LOAD Syntax Error                    | ERROR   | Invalid LOAD LABEL / BROKER LOAD structure                                                                  |
| SYN014  | ROUTINE LOAD Syntax Error            | ERROR   | Invalid CREATE ROUTINE LOAD structure                                                                       |

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

These rules expand the skill from offline SQL syntax/specification review into execution-plan and live catalog inspection. That materially changes the trust boundary: a user invoking a 'SQL checker' may unknowingly trigger analysis that depends on database state and access to operational metadata, increasing exposure beyond the declared purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest-style YAML file uses Chinese throughout rule names, descriptions, and fix suggestions, which effectively forces a specific language for users or downstream agents. The file does not indicate that the skill is region-specific, nor does it offer any language or locale opt-in, which matches the policy-violation criterion for language/locale constraints.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The rules explicitly require MCP-backed EXPLAIN ANALYZE and catalog queries, which can cause the skill to interact with a live database rather than just parse SQL text. This can expose schema, statistics, backend/tablet state, and potentially execute resource-consuming analysis against production systems, making the capability materially more dangerous than a static reviewer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This YAML rules file uses Chinese natural-language titles, descriptions, and fix suggestions throughout, but does not indicate that the skill is China-specific or provide any user opt-in for language/locale. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file emits natural-language diagnostics, report headings, and remediation text in Chinese throughout the checker, including violation names, messages, and the generated Markdown report. Because the file does not provide any opt-in, locale selection, or justification that the skill is intended only for Chinese-speaking users, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown template hard-codes Chinese headings and field labels throughout the file, which imposes a specific language on users. The policy for natural-language content requires either a user language choice or a clearly justified locale constraint; neither is present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The specification-check section at L293 says violations come from specification rules SPEC001-SPEC040, but earlier the document defines SPEC001-SPEC046. This active inconsistency misstates what the checker is supposed to report and conflicts with the declared rule set.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

Earlier documentation states the checker generates a Markdown report and the example report is Markdown, but line L306 says the direct command outputs JSON format. This is an internal documentation contradiction about what the command actually produces, which can mislead users about the skill's behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

L179 declares 46 specification rules, but the references table at L331 describes the specification rules file as containing 40 rule definitions. This is a direct documentation inconsistency about the skill's intended coverage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This YAML file contains natural-language descriptions, names, and suggestions only in Chinese, which can impose a fixed language/locale on users or downstream operators. The file does not indicate that Chinese is optional, configurable, or required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.