Back to skill

Security audit

Index Optimization

Security checks for vulnerabilities and agentic risk

Overview

This skill is for database index optimization, but it defaults to allowing schema-changing index creation or deletion without explicit user approval.

Review before installing. Use this only with explicit confirmation-required mode, non-production targets, and read-only credentials for discovery and EXPLAIN until you intentionally approve a specific DDL statement. Do not allow automatic DROP INDEX or dropIndex operations on production databases.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:15
Finding

Database Index Changes May Execute Without Explicit User Approval

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15-18, 89-99, and 110-115
Vulnerability Type: Unsafe default authorization for schema-changing database operations
Risk Level: High

Vulnerable Code Snippets

Faithful English translation of SKILL.md, lines 15-18:

markdown
- Execution confirmation mode (optional):
  - Not specified: `No-confirmation mode` (default; index creation/deletion can be executed directly without waiting for user confirmation)
  - Specified: `Confirmation-required mode` (user confirmation is required before creating/deleting indexes)

Faithful English translation of SKILL.md, lines 89-99:

markdown
### 4) Provide justification before changes

Before creating/deleting an index, output:
1. Change type.
2. Change justification.
3. Risk assessment.
4. Statement to execute.

Proceed according to the execution confirmation mode:
- `Confirmation-required mode`: only proceed after explicit user confirmation.
- `No-confirmation mode`: proceed directly without waiting for user confirmation.

Faithful English translation of SKILL.md, lines 110-115:

markdown
### 5) Execute index changes and run EXPLAIN

1. SQL databases: write DDL to the index-optimization SQL file.
2. MongoDB: output createIndex and corresponding dropIndex rollback statements.
3. Run EXPLAIN before and after the index changes.
4. Record whether the target index is used.
5. For removal of an old index, validate the replacement before executing deletion.

Technical Analysis

The Skill makes no-confirmation execution the default and explicitly permits immediate index creation or deletion. These are schema-changing operations with material availability and performance consequences. A rollback statement and EXPLAIN validation reduce operational risk but do not constitute authorization.

The behavior also conflicts with agents/openai.yaml:4, whose default prompt ...[truncated 2185 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make Confirmation-required mode the default whenever no mode is specified.
  2. Require explicit, operation-specific approval immediately before every schema-changing statement is executed.
  3. Present the exact target database, environment, table or collection, index name, DDL statement, expected locking behavior, and rollback statement in the approval request.
  4. Never automatically execute index deletion. Treat every proposed removal as advisory until separately approved.
  5. Restrict automatic execution, if retained at all, to an explicitly selected non-production environment and reject ambiguous environment configurations.
  6. Use a read-only database account for discovery and EXPLAIN stages. Acquire narrowly scoped DDL capability only after approval.
  7. Validate replacement indexes against representative production workload evidence, database index-usage statistics, and before-and-after execution plans rather than repository search results alone.
  8. Add database-native safeguards where available, such as online DDL options, lock timeouts, maintenance windows, and monitoring with automatic abort thresholds.
  9. Reconcile SKILL.md with agents/openai.yaml so both consistently require confirmation.
  10. Record an immutable audit entry containing the approver, target environment, exact operation, execution result, and rollback status.
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个数据库查询优化/索引分析技能,重点包括查询模式分析、索引设计、explain 验证,以及多种操作模式。实际代码仅对代码仓库执行文本搜索,收集与某个表/集合相关的查询位置并分类展示。它访问的资源是本地仓库文件和外部 rg 命令,而不是数据库;输出是清单式 inventory,而不是优化建议或验证结果。虽然“定位该表/集合所有查询”与脚本部分行为有一点相关,但整体主目的和关键能力与声明相比明显不足且不同,因此属于实质性不匹配。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill defaults to '免确认模式' and explicitly allows immediate index creation or deletion without waiting for user confirmation. Because DDL changes can degrade performance, lock tables, break query plans, or remove critical indexes, making destructive database changes the default is a high-risk behavior, especially when driven by an agent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes shell commands such as python3, rg, mysql, psql, and mongosh but does not declare any tool scope or allowed-tools boundaries. Without explicit scoping, an agent may be permitted to execute broader shell actions than intended, increasing the risk of unsafe command execution and environment access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill manifest description is written entirely in Chinese and does not indicate any user language choice or opt-in behavior. This can violate language/locale policy when a skill implicitly assumes a specific language rather than offering the user's preferred language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all instructional content in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/collect_table_queries.py (reported line 62)May include surrounding context.

python
cmd.extend(str(p) for p in search_roots if p.exists())

    try:
        proc = subprocess.run(
            cmd,
            capture_output=True,
            text=True,

Static analysis

No suspicious patterns detected.