T09 · Insecure Skill Coding Practices
- Location
scripts/postgres_tool.py:143- Finding
Read-only query restriction bypass through data-modifying PostgreSQL CTEs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill performs useful PostgreSQL tasks, but its database-change safety controls, credential handling, and installation guidance are risky enough to require review before installation.
Install only after review in a controlled environment. Use a dedicated least-privilege PostgreSQL role, remove the bundled postgres/postgres config, avoid sudo/admin installation, pin and verify dependencies, keep backups outside the skill package with restricted permissions, and do not rely on the advertised read-only, backup, restore, force, or dry-run protections for production data without code fixes.
scripts/postgres_tool.py:143Read-only query restriction bypass through data-modifying PostgreSQL CTEs
scripts/postgres_tool.py:458Backup and confirmation safeguards are not bound to the SQL target table
scripts/postgres_tool.py:337SQL injection through attacker-controlled restore metadata and CSV column names
config/db_config.json:1Hardcoded plaintext PostgreSQL administrative credential
scripts/postgres_tool.py:237Sensitive database records are written to unencrypted, access-unrestricted backup files
scripts/requirements.txt:5Unpinned and unhashed third-party dependency installation
The stated purpose is database management, but the skill also includes environment inspection, dependency diagnostics, filesystem inspection, and package-management workflows. This mismatch can cause an agent or user to authorize the skill for database tasks while it performs unrelated local-system operations, expanding attack surface and creating opportunities for privilege misuse.
The skill instructs use of rm -rf with a wildcard to delete dependency artifacts. Although the path is relatively specific, destructive shell patterns in agent-facing documentation are dangerous because path confusion, variable substitution, or working-directory mistakes can delete unintended files.
cd .qoder/skills/postgres-tool
# 删除旧的依赖文件(如果有)
rm -rf scripts/dependencies/*.whl # Linux/Mac
del /Q scripts\dependencies\*.whl # Windows
# 下载与当前 Python 版本匹配的 wheel 文件
A second destructive deletion example repeats the same unsafe shell pattern, reinforcing risky operational behavior. In combination with shell-capable agents, such commands can be copied or adapted in ways that broaden deletion scope and damage local environments.
# 删除所有 wheel 文件并重新下载
cd .qoder/skills/postgres-tool
rm -rf scripts/dependencies/*.whl # Linux/Mac
del /Q scripts\dependencies\*.whl # Windows
# 重新下载
The skill documents shell execution, filesystem reads/writes, and exporting data, but declares no explicit tool scope or permission boundaries. In an agent setting, this increases the chance the skill is invoked with overly broad capabilities, enabling unintended command execution, local file access, or data export beyond user expectations.
The invocation guidance says to use this skill whenever users need PostgreSQL help, without clear boundaries on safe query classes, credential handling, or operation risk. Overly broad triggering can cause the agent to route common requests into a high-capability skill that can access databases, files, and shell commands unnecessarily.
The skill description begins in Chinese and presents the operational guidance in that language without indicating that another language can be used. This can violate language or locale policy where user choice or opt-in is required rather than assuming a fixed language.
Automatically searching for and loading db_config.json from multiple local paths encourages implicit credential discovery and connection behavior without prominent warnings about secrets handling. In an agent environment, this can lead to unintended use of locally stored database credentials and accidental access to sensitive databases.
The documentation advises running installation with sudo, which elevates package installation and script execution to root privileges. If the dependency directory or install script is tampered with, this can turn a routine setup step into full system compromise.
解决方案:
# Windows:以管理员身份运行 PowerShell
# Linux/Mac:使用 sudo
sudo ./install-dependencies.sh
# 或者安装到用户目录
The adjacent instruction still normalizes root-level execution for dependency installation, amplifying the risk from any compromised script or package artifact. In a skill that already uses shell and local files, combining setup steps with privilege escalation materially increases blast radius.
# Windows:以管理员身份运行 PowerShell
# Linux/Mac:使用 sudo
sudo ./install-dependencies.sh
# 或者安装到用户目录
pip install --user --no-index --find-links=./scripts/dependencies -r scripts/requirements.txt
The documentation claims only SELECT is allowed by default, yet elsewhere instructs direct execution of SQL and provides UPDATE/DELETE flows including a force flag. Conflicting guidance weakens safety assumptions and may lead an agent to execute destructive or exfiltrative SQL under the belief that the tool is read-only.
All natural-language prompts and expected outputs are written in Chinese, and the file provides no indication that this is an optional locale or a region-specific skill. That can violate language/locale policy because it implicitly constrains usage to a specific language without offering choice or documenting justification.
This markdown file presents the skill examples and instructions entirely in Chinese, starting from the title and introductory text, with no indication that users may choose another language. Under the policy rules, forcing a specific language without user opt-in is a natural-language policy violation unless clearly justified as region-specific.
The guide tells users to create and edit db_config.json but provides no warning that this file will likely contain sensitive database credentials and connection details. In an internal deployment context, users may store plaintext secrets in the project directory, accidentally commit them, share them over removable media, or leave them with overly broad filesystem permissions.
The examples run SQL directly against a live database and do not clearly emphasize read-only usage, non-production targets, or the risk of destructive statements. Because this skill is specifically for PostgreSQL management, operators may assume arbitrary SQL is acceptable and accidentally execute harmful queries against production data.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Linux/Mac:
sudo ./scripts/install-dependencies.sh
The file’s instructional content is written entirely in Chinese, beginning with the title at L01 and continuing throughout the guide, with no indication that users may choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
The documentation explicitly states that TRUNCATE TABLE is 'not in this skill's supported range,' which narrows the skill's documented scope beyond the manifest's broader claim of PostgreSQL database management. This creates intent-level inconsistency between the skill documentation and its stated purpose, because the guide frames a database operation as unsupported without any corresponding manifest limitation.
The module docstring and all user-facing strings are written exclusively in Chinese, which imposes a specific language on users. The file does not indicate that Chinese is optional, configurable, or required for a region-specific purpose, so this is a natural-language locale policy concern.
The manifest describes a PostgreSQL management tool for connecting to databases, querying data, inspecting schemas, exporting results, and safely performing UPDATE/DELETE operations. This file instead implements a general environment and package-installation diagnostic utility, including pip checks and installation guidance, which is not part of the stated database-management behavior.
A PostgreSQL management skill would be expected to interact with databases and local exports, but spawning subprocesses to run pip is a separate package-management capability. The manifest does not mention environment administration or dependency tooling, so this capability is broader than the declared purpose.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
import subprocess
try:
result = subprocess.run([sys.executable, "-m", "pip", "--version"],
capture_output=True, text=True, timeout=5)
if result.returncode == 0:
print(f"✓ Pip 版本:{result.stdout.strip()}")
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
import subprocess
try:
result = subprocess.run([sys.executable, "-m", "pip", "list"],
capture_output=True, text=True, timeout=10)
if result.returncode == 0:
installed_lines = result.stdout.strip().split('\n')[2:] # 跳过表头
The module description and all user-facing prompts/messages are in Chinese, which imposes a specific language on users. The file does not provide any mechanism to select another language or document that the skill is intentionally region-specific.
The manifest and module docstring describe querying, schema inspection, export, safe UPDATE/DELETE, and recovery, but this recovery implementation is itself a broad write capability: it can INSERT rows, UPSERT with ON CONFLICT, and DELETE-then-INSERT in replace mode. That goes beyond the specifically described modification scope of safe UPDATE/DELETE operations and materially expands write behavior.
This JSON manifest-like file contains only Chinese prompt examples for invoking the skill, but it does not clarify whether the skill is intended to activate only for Chinese requests or whether other languages are supported. In a manifest/evals context, that creates ambiguity about trigger scope and may cause unintended assumptions about when the skill should apply.
No suspicious patterns detected.