Back to skill

Security audit

Aloudata CAN SKILLS - text-to-sql-query

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Text-to-SQL database helper, but it gives broad direct query access to sensitive retail/customer fields without privacy scoping and recommends bypassing proxies.

Install only in an environment where users are authorized to query this retail database. Prefer a restricted gateway role or approved analytics views, remove the global proxy bypass, audit queries, and require redaction or approval before returning member, employee, address, order-level, or other person-level records.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:43
Finding

Forced bypass of configured network proxies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:43-47 and SKILL.md:67-71
Vulnerability Type: Network security control bypass
Risk Level: Medium

Vulnerable Code

bash
curl --noproxy '*' -s \
  -H "X-API-Key: $CAN_API_KEY" \
  -H "Content-Type: application/json" \
  -X POST "https://gateway.can.aloudata.com/api/jdbc/query" \
  -d '{"sql": "YOUR SQL HERE"}'

The multiline SQL example repeats the same behavior:

bash
curl --noproxy '*' -s \
  -H "X-API-Key: $CAN_API_KEY" \
  -H "Content-Type: application/json" \
  -X POST "https://gateway.can.aloudata.com/api/jdbc/query" \
  -d @- <<'EOF'

Technical Analysis

The recommended curl commands use --noproxy '*', which disables proxy use for every destination. This forces the request to connect directly to the external SQL gateway, even when the execution environment has configured an enterprise proxy.

The direct HTTPS request is part of the Skill's declared functionality, and transmitting $CAN_API_KEY to the declared gateway as an authentication header is not independently evidence of credential exfiltration. However, globally bypassing proxy configuration is not necessary to perform that request. It can circumvent network inspection, egress filtering, audit logging, destination controls, and other organization-level security policies.

Attack Path

  1. An operator invokes the Skill in an environment configured to route outbound traffic through a controlled proxy.
  2. The Agent follows the recommended curl execution method.
  3. --noproxy '*' disables the configured proxy for the request.
  4. The Agent sends an authenticated SQL request directly to gateway.can.aloudata.com.
  5. Proxy-based monitoring, filtering, and audit controls do not observe or enforce policy on the connection.

Impact Assessment

This behavior does not directly grant local system privileges or expose the API key to an undeclared d ...[truncated 400 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove --noproxy '*' from all recommended commands and allow the runtime's standard proxy configuration to apply.
  • If a direct connection is operationally required, make proxy bypass optional rather than mandatory.
  • Restrict any approved bypass to the exact trusted hostname instead of using the global * wildcard.
  • Document why direct connectivity is required and require deployment-specific administrator approval.
  • Keep HTTPS certificate verification enabled and do not add insecure TLS options.
  • Use a scoped, short-lived API credential and ensure commands, headers, and environment variables are not written to logs.
  • Enforce destination restrictions and request auditing independently at the gateway.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:270
Finding

Person-level retail data can be queried without data-minimization controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:130, SKILL.md:242-253, and SKILL.md:270-275
Vulnerability Type: Excessive access to personal and operational data
Risk Level: High

Vulnerable Schema Exposure

The order schema exposes a member identifier:

text
| vip_code | varchar | 会员编码 |

The shop schema exposes employee identity and address fields:

text
| shop_leader | varchar | 店长姓名 |
| shop_leader_code | varchar | 店长编码 |
| shop_status | varchar | 门店状态 |
| shop_status_code | varchar | 门店状态编码 |
| province | varchar | 省份 |
| province_id | bigint | 省份 ID |
| city | varchar | 城市 |
| city_id | bigint | 城市 ID |
| city_grade | varchar | 城市等级 |
| city_grade_id | bigint | 城市等级 ID |
| district | varchar | 区县 |
| address | varchar | 地址 |

The member dimension exposes direct person-level identifiers:

text
| dt | date | 数据日期 |
| vip_id | bigint | 会员 ID(主键) |
| vip_code | varchar | 会员编码 |
| vip_name | varchar | 会员姓名 |

Technical Analysis

The Skill authorizes the Agent to generate arbitrary SELECT statements over six whitelisted tables, including dim_vip, dim_shop, and fact_orders. Those tables contain customer names and identifiers, employee identities, addresses, order identifiers, seller information, and related transaction records.

The documented controls limit statements to read-only queries, prohibit multiple statements and UNION, impose a table allowlist, and apply a result limit. These controls reduce database integrity risks but do not provide confidentiality protection. The Skill does not instruct the Agent to:

  • Mask or omit direct identifiers.
  • Prefer aggregate results over person-level records.
  • Apply row-level or column-level authorization.
  • Verify that the requester is authorized to access customer or employee data.
  • Enforce minimum aggregation-group sizes.
  • Reject bulk identity or transaction-history requests.

C ...[truncated 1744 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove direct identifiers such as vip_name, vip_code, employee names, and employee codes from the Agent-accessible schema unless explicitly required.
  • Expose a restricted analytics view containing only approved, masked, or aggregated fields instead of granting access to base tables.
  • Enforce column-level and row-level authorization at the gateway or database layer; prompt instructions alone are not a sufficient control.
  • Use separate API credentials and roles for aggregate analytics and authorized person-level support workflows.
  • Require explicit authorization and purpose validation before permitting person-level queries.
  • Mask identifiers by default and reveal them only through a separately audited workflow.
  • Enforce minimum aggregation-group sizes to reduce singling-out and re-identification risks.
  • Apply strict per-request and cumulative query limits to prevent enumeration through pagination or repeated filtered requests.
  • Add gateway-side audit logging and alerts for direct-identifier selection, broad member queries, and repeated extraction patterns.
  • Prevent the Agent from automatically displaying sensitive gateway results; require redaction and sensitivity review first.
  • Retain the existing read-only, table-allowlist, timeout, and statement-count controls as defense-in-depth measures.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger description is broad enough that ordinary analytics requests may invoke this skill and cause direct database querying without clear user intent or least-privilege gating. In practice, this increases the chance of oversharing sensitive retail, customer, or membership data because the skill bypasses any semantic or policy layer and goes straight to SQL execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill performs direct SQL queries over tables that include customer and membership fields such as vip_id, vip_code, vip_name, addresses, and shop personnel data, yet it provides no warning or consent boundary about sensitive data exposure. That omission makes unsafe querying more likely and normalizes returning potentially personal or business-confidential data to users without minimization.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The curl example provides a concrete mechanism to send arbitrary generated SQL to an external endpoint using a live credential, which is a classic external transmission capability. In the context of a direct Text-to-SQL skill over retail orders, inventory, shops, and VIP data, this makes unauthorized or excessive data extraction significantly easier if the skill is invoked inappropriately or manipulated by prompts.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

方式一:curl(推荐,适合 Bash 环境)

bash
curl --noproxy '*' -s \
  -H "X-API-Key: $CAN_API_KEY" \
  -H "Content-Type: application/json" \
  -X POST "https://gateway.can.aloudata.com/api/jdbc/query" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The Python example operationalizes external transmission by sending SQL requests and an API key-backed authorization header to a remote service. Even if the gateway enforces SELECT-only and table whitelisting, the skill still enables remote extraction of sensitive records and metadata from approved tables, including VIP and shop-related information.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

python
import os, requests

response = requests.post(
    "https://gateway.can.aloudata.com/api/jdbc/query",
    headers={
        "X-API-Key": os.environ["CAN_API_KEY"],

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The Python example operationalizes external transmission by sending SQL requests and an API key-backed authorization header to a remote service. Even if the gateway enforces SELECT-only and table whitelisting, the skill still enables remote extraction of sensitive records and metadata from approved tables, including VIP and shop-related information.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

python
import os, requests

response = requests.post(
    "https://gateway.can.aloudata.com/api/jdbc/query",
    headers={
        "X-API-Key": os.environ["CAN_API_KEY"],

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L637 要求“列名使用中文展示名”,属于对输出语言的强制性限制,但文档没有提供用户语言偏好选择,也没有说明该技能仅服务于必须使用中文的特定合规区域。按照语言/locale 政策,这类固定语言要求在缺乏用户选择或明确正当性时构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest frames the skill as generating and executing SQL against a retail database. In SKILL.md, the skill explicitly requires reading $CAN_API_KEY from environment variables to authenticate outbound requests, which is a credential-access capability not described in the manifest itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.