Back to skill

Security audit

huawei-cloud-dws-sql-check

Security checks for vulnerabilities and agentic risk

Overview

This is a local DWS SQL linting skill with no network, credential, persistence, or destructive behavior, though its documentation overstates check coverage.

Install only if you want an offline, local DWS SQL advisory checker. Do not treat a clean report as proof of complete SQL safety, compliance, performance, or production readiness, especially for generic SQL audit or optimization requests.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill makes strong claims about comprehensive syntax, specification, naming, and grammar validation, but the finding indicates the implementation likely does not deliver that coverage. This can create a false sense of assurance: users may trust 'passed' results for SQL safety, compliance, or correctness when important checks are actually missing, leading to unsafe or noncompliant SQL being approved.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

md
| [Keywords](rules/keywords.py) | 594 DWS SQL keyword definitions |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 278)May include surrounding context.

md
| [Grammar Rules](rules/grammar_rules.py) | 160+ statement type grammar definitions |

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/dws_sql_parser.py (reported line 558)May include surrounding context.

python
return node

    # ============================================================
    # DELETE Statement Parser
    # ============================================================

    def _parse_delete(self):

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/dws_sql_parser.py (reported line 562)May include surrounding context.

python
# ============================================================

    def _parse_delete(self):
        """Parse DELETE statement"""
        node = ASTNode("DeleteStmt")
        start_token = self._current()

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/dws_sql_parser.py (reported line 860)May include surrounding context.

python
action_tokens.append(self._advance())
        node.children["actions"] = self._tokens_to_text(action_tokens).strip()

        node.tokens = [start_token]
        node.raw_text = self._get_raw_text(start_token)
        return node

    # ============================================================
    # DROP Parser
    # ============================================================

    def _parse_drop(self):
        """Parse DROP statement"""
        node = ASTNode("DropStmt")
        start_token = self._current()

        self._advance()  # skip DROP

        # Object type
        obj_types = ["TABLE", "INDEX", "VIEW", "SEQUENCE", "SCHEMA", "DATABASE",
                    "FUNCTION", "PROCEDURE", "TRIGGER", "TYPE", "DOMAIN", "ROLE",
                    "USER", "GROUP", "TABLESPACE", "EXTENSION", "FOREIGN",
                    "SYNONYM", "MATERIALIZED", "NODE", "OUTLINE", "DIRECTORY",
                    "PUBLICATION", "SUBSCRIPTION", "RESOURCE", "WORKLOAD"]
        obj_type = None

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Overly broad trigger phrases like general SQL review/audit terms can cause the skill to activate for requests outside its real capability boundary. In combination with the claimed comprehensive checking, this increases the chance the agent will inappropriately handle broad SQL security, optimization, or audit tasks and return incomplete or misleading guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest-style YAML contains all human-readable names, descriptions, and fix suggestions in Chinese, which imposes a specific language/locale on users. The file does not offer any language choice or document that the skill is intentionally limited to a Chinese-speaking or region-specific environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This YAML file defines all rule names, descriptions, check logic, and fix suggestions exclusively in Chinese, which imposes a specific language on users of the skill. The file does not document that the skill is intended only for a Chinese-speaking or region-specific environment, nor does it offer any language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code embeds natural-language rule names and categories in Chinese and later renders them directly in reports, making the skill effectively enforce a specific language. The file does not provide an opt-in, fallback, or justification that the tool is intentionally limited to a Chinese-language audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.