Back to skill

Security audit

huawei-cloud-mrs-clickhouse-sql-check

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local ClickHouse SQL checker with some overstated coverage claims, but I found no hidden network access, credential use, persistence, or destructive behavior.

Install only if you want an offline advisory ClickHouse SQL checker. Do not rely on it as a complete ClickHouse parser, and avoid pasting secrets into SQL examples because reports may echo the original SQL. Treat any generated DROP, DELETE, BACKUP, or RESTORE guidance as review-only unless you independently verify before execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description promises a full SQL checking skill with two modes (syntax and specification), multi-version ClickHouse support, a built-in tokenizer, and recognizer/checker behavior. The supplied code chunk is instead a data-definition module for ClickHouse 22.3 grammar rules. It enumerates many statement types and provides grammar dictionaries for a limited subset (e.g., SELECT, INSERT, CREATE TABLE, ALTER TABLE, BACKUP/RESTORE), plus helper lookup functions. There is no code here that tokenizes SQL, parses input, validates statements, enforces development specification rules, or performs optimization/review. While this module could be a supporting component of such a system, by itself it does not accurately represent the declared end-user capability, so the description overstates what the provided code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This code chunk is a low-level supporting component for a lexer: an enum of token types, token classification sets, helper predicates, and operator precedence mappings specific to ClickHouse 22.3. That is related to the declared domain, but it does not itself implement the declared primary behavior of a comprehensive SQL checker. The description promises end-user validation features such as syntax checking, statement recognition, ClickHouse-specific clause validation, and specification compliance checks across multiple versions. None of those behaviors are present in this chunk. Because the actual functionality shown is substantially narrower than the declared purpose, this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description is broader than what this specific code chunk actually does. The file is a data/metadata module containing a StatementType enum and partial grammar definitions for ClickHouse 23.3, with helper functions to retrieve those definitions. While it aligns with part of the declared syntax-checking domain, it does not itself perform SQL checking, tokenization, statement recognition, specification validation, or optimization. It also does not demonstrate multi-version behavior beyond comments comparing 23.3 with 24.8. This is a material description-to-behavior mismatch for the supplied chunk, even if this file could be a supporting component within a larger checker.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a full-featured SQL checking skill with syntax and specification validation, custom tokenization, multi-version support, and broad statement recognition. The supplied code chunk is much narrower: it is a data-definition module containing grammar rule dictionaries and helper lookup functions for ClickHouse 24.8. While it aligns partially with the syntax-checking theme and includes ClickHouse-specific clause metadata, it does not itself implement the claimed checker behavior, tokenizer, or specification validation. There is no evidence of undeclared harmful behavior; the mismatch is that the description substantially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code largely aligns with part of the declared purpose: it does parse/tokenize ClickHouse SQL, load version-specific keywords, detect many statement types, and run some syntax checks. However, the description substantially overstates what this code chunk actually does. There is no visible implementation of the specification-check mode or SPEC001-SPEC035 rules. The syntax checker is basic rather than comprehensive: it validates only a small subset of structures (SELECT ordering, CREATE TABLE ENGINE/ORDER BY heuristics, DELETE/UPDATE clause presence, parentheses, lexer errors, reserved keywords), not the broad ClickHouse grammar coverage claimed (e.g., SAMPLE BY, FINAL, ARRAY JOIN, PREWHERE semantics, GLOBAL/ASOF JOIN rules, PARTITION BY, TTL, etc.). Also, the declared multi-version support includes 22.3, while this file's usage/help text mentions only 24.8 and 23.3. This is an overclaim rather than an undeclared capability, but it still means the declared description does not accurately represent the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code chunk is a tokenizer, not a full SQL checker. It recognizes tokens, merges compound keywords, tracks version-specific keyword sets, and reports lexical issues such as unclosed strings/comments or unexpected characters. However, the declared description promises significantly broader behavior: syntax validation of ClickHouse statements, clause completeness checks, compatibility checks for many ClickHouse constructs, statement-type recognition, and specification compliance checks against a development standard. None of those higher-level analysis capabilities appear in this code chunk. While the tokenizer could be a supporting component of such a system, this chunk by itself does not accurately represent the declared end-user functionality, so the description materially overstates what the code actually does.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 403)May include surrounding context.

md
| [Keywords v24.8](rules/v24.8/keywords.py) | 571 ClickHouse 24.8 keyword definitions |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 404)May include surrounding context.

md
| [Keywords v23.3](rules/v23.3/keywords.py) | 462 ClickHouse 23.3 keyword definitions |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 405)May include surrounding context.

md
| [Keywords v22.3](rules/v22.3/keywords.py) | 422 ClickHouse 22.3 keyword definitions |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 409)May include surrounding context.

md
| [Grammar v24.8](rules/v24.8/grammar_rules.py) | 24.8 statement type grammar definitions |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 410)May include surrounding context.

md
| [Grammar v23.3](rules/v23.3/grammar_rules.py) | 23.3 statement type grammar definitions |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 411)May include surrounding context.

md
| [Grammar v22.3](rules/v22.3/grammar_rules.py) | 22.3 statement type grammar definitions |

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/ck_sql_parser.py (reported line 332)May include surrounding context.

python
def validate_delete_syntax(tokens: List[Token]) -> List[Dict]:
    """Validate DELETE statement syntax."""
    violations = []
    has_where = False
    has_from = False

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/ck_sql_parser.py (reported line 362)May include surrounding context.

python
def validate_delete_syntax(tokens: List[Token]) -> List[Dict]:
    """Validate DELETE statement syntax."""
    violations = []
    has_where = False
    has_from = False

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrases are broad enough to activate on ordinary SQL-help or optimization requests, which can cause the agent to invoke this skill in contexts the user did not intend. Over-broad routing is dangerous because it can override more appropriate skills, create confusing autonomous behavior, and increase the chance that untrusted SQL text is processed under the wrong assumptions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
are stored in `rules/v{version}/` directories. Common development-spec rules are in
`rules/common/`. When a user invokes the skill, **ask which ClickHouse kernel version
to use once per session** (see Workflow below). Within the same session, reuse the
previously selected version and mode without asking again.

**Supported Versions**:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
are stored in `rules/v{version}/` directories. Common development-spec rules are in
`rules/common/`. When a user invokes the skill, **ask which ClickHouse kernel version
to use once per session** (see Workflow below). Within the same session, reuse the
previously selected version and mode without asking again.

**Supported Versions**:

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
**Typical Use Cases**:
- "Check this SQL: SELECT * FROM t1"
- "Does this CREATE TABLE have valid ClickHouse syntax?"
- "Validate the syntax of this MERGE statement"
- "Check if my SQL uses ClickHouse-specific syntax correctly"
- "Check if this ClickHouse SQL syntax is correct"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
`<=>` (NULL-safe equality, 24.8 only), `<>` / `!=` (not equals)
- Literals: strings (single-quoted), numbers (int/float/hex), identifiers (bare/backtick/quoted)
- Comment skipping (-- single line, /* */ multi-line with nesting support)
- Compound keyword recognition (ORDER BY, GROUP BY, CREATE TABLE, etc.)
- Error detection (unclosed strings, invalid characters, etc.)

### Step 3: Statement Recognition & Parsing

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file lists destructive operations such as DROP COLUMN, DROP PARTITION, DELETE, UPDATE, and DROP DATABASE/TABLE as raw syntax references, but it does not include any warning that these actions can delete data or alter system state irreversibly. Under the markdown-specific SQP-2 criteria, descriptions that cover behaviors affecting user data or system integrity should disclose those risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file documents DELETE syntax and explicitly distinguishes it as a mutation, but it does not warn that executing the statement changes or removes table data. For markdown files, safety-impacting behavior that can affect user data should include some disclosure so readers understand the operational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The BACKUP / RESTORE section includes forms such as TO [user:password@]host[:port] and remote destinations like S3/Azure, which can involve sensitive credentials and movement of data to external systems. The documentation does not include any warning about protecting credentials, validating destinations, or the potential impact of restore operations on data/system state.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring states it 'defines all statement types and their grammar structures for syntax validation,' and the enum lists many supported statement types. However, the registry at L649-L658 only includes 8 grammar definitions, so functions like get_grammar cannot provide grammar for most declared statement types such as GRANT, REVOKE, SHOW, SYSTEM, BACKUP, and many DDL forms.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The function returns list(StatementType), which includes dozens of enum values that are not present in GRAMMAR_REGISTRY. This contradicts the stated intent of returning 'supported' statement types, since other module behavior only supports grammar retrieval for the registered subset.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/version_loader.py:50