Back to skill

Security audit

KWDB Text2SQL AIoT

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent KWDB text-to-SQL helper, with database access risks that are disclosed and tied to its purpose.

Install this only for KWDB workflows and connect it to an MCP server/account that is authorized for the target databases. Review generated SQL before approving execution, especially write, DDL, DROP, DELETE, UPDATE, or ALTER statements, and avoid broad schema discovery where database names or table definitions are sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger 'query KWDB database' is broad enough that generic database or SQL-related requests may invoke this skill even when the user did not intend KWDB-specific behavior. That can cause misrouting, incorrect SQL generation, and unsafe follow-on actions such as schema discovery or execution prompts against the wrong environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger 'write SQL for KWDB' is still ambiguous because users may request SQL writing in mixed-database contexts or without intending this skill to take over execution-oriented workflow. Overbroad activation increases the chance that the skill applies KWDB-specific syntax, schema assumptions, or execution steps to unrelated requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow instructs the agent to ask the user for the database name using a Chinese-only prompt, and similar mandated Chinese prompts appear elsewhere. This imposes a language choice without offering the user an opt-in or alternative, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This fallback step requires asking for schema information using a Chinese-only prompt. Because the file does not state that the skill is region-specific or that the user can choose the language, it effectively enforces a locale without consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The execution confirmation step tells the agent to prompt in Chinese and accept Chinese response words such as "是" and "执行". This is a language policy issue because it requires a specific language/locale without user opt-in or a documented regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The "Use for" section lists only Chinese phrases as the activation/use cues, which imposes a language-specific interaction pattern. The file does not offer alternative languages, user opt-in, or any justification that this skill is intentionally limited to a Chinese-language environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file uses Chinese-only natural-language examples such as "最新温度" and "最近一条记录" to describe when the skill should be used. This imposes a specific language context without user opt-in or a documented justification that the skill is intended only for a Chinese-language environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The guidance instructs the agent to enumerate databases, tables, and full table definitions to generate SQL, but it does not require a user-consent or least-privilege check before exposing potentially sensitive schema metadata. In an MCP-integrated environment, schema names and DDL can reveal business context, identifiers, or sensitive data structure, so automatic discovery increases unnecessary metadata exposure even if only read-only commands are used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entry for clock_timestamp() contains the Chinese term 变化, while the rest of the document is in English. This introduces a language inconsistency without offering a language choice or documenting a justified locale-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'Natural Language Mapping' table presents all natural-language examples in Chinese, which effectively imposes a specific language/locale in the skill content. The file does not indicate that Chinese is optional, user-selectable, or required for a documented region-specific reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The routing rules and keyword mappings explicitly hard-code both Chinese and English trigger terms, implying language-specific behavior, but the document does not state whether users may use other languages or whether the skill is intentionally limited to these locales. Under the language/locale policy check, this can be read as forcing a specific set of languages without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown reference is primarily written in English, but the data type table, warning block, and natural-language mapping switch to Chinese. The file does not indicate that the bilingual or Chinese-specific content is intentional, optional, or limited to a particular locale, which can violate language-choice expectations under the policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown includes user-facing trigger and usage text in Chinese while other sections are in English, but it does not indicate that the skill is intended only for Chinese-speaking users or provide an opt-in language choice. Under the policy, forcing or assuming a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several explanatory headings, table entries, and notes in the latter half of the file are written only in Chinese, while the rest of the document is in English. There is no explicit justification that this is a region-specific or Chinese-only skill, so the file imposes a language constraint without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.