Back to skill

Security audit

Db Explorer

Security checks for vulnerabilities and agentic risk

Overview

This database helper is not malicious, but it needs review because it includes powerful export, restore, and migration commands that can expose or alter data if copied directly.

Install only if you are comfortable with an agent helping run database CLI commands. Use least-privileged, non-production credentials where possible; avoid pasting real passwords into command lines; confirm the exact target database before exports, restores, imports, or migrations; and prefer private, access-controlled output locations instead of shared /tmp paths.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:49
Finding

Database Credentials Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 49–51, 64–65, and 68–70
Vulnerability Type: Credentials exposed through process arguments and shell history
Risk Level: Medium

Vulnerable Code

bash
# PostgreSQL
psql "postgresql://user:password@host:5432/dbname" -c "\dt"
psql "postgresql://user:password@host:5432/dbname" -c "\d table_name"
psql "postgresql://user:password@host:5432/dbname" -c "SELECT count(*) FROM table_name;"

# MongoDB
mongosh "mongodb://user:password@host:27017/dbname" --eval "db.getCollectionNames()"
mongosh "mongodb://user:password@host:27017/dbname" --eval "db.collection_name.countDocuments()"

# Redis
redis-cli -h host -p 6379 -a password INFO keyspace
redis-cli -h host -p 6379 -a password DBSIZE
redis-cli -h host -p 6379 -a password KEYS "*"

Technical Analysis

The examples encourage users to place database passwords directly in command-line arguments. Real credentials substituted into these commands can be retained in shell history and may be visible through local process-inspection interfaces, diagnostic tools, audit logs, or command telemetry.

This behavior conflicts with the safety rule in SKILL.md line 78 that states passwords should not be placed in history. Quoting a connection URI does not prevent the complete argument from being recorded or exposed.

Attack Path

  1. A user replaces the placeholder password with a real database credential.
  2. The command is recorded in shell history or appears in the process argument list while executing.
  3. Another local user, monitoring service, support bundle, or telemetry collector obtains the command text.
  4. The exposed credential is extracted from the URI or password argument.
  5. The attacker connects to the affected database and performs operations permitted by that database account.

Impact Assessment

Exploitation can disclose PostgreSQL, MongoDB, or Redis credentials. The resulting p ...[truncated 387 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove credential-bearing connection strings and redis-cli -a password from command examples.
  • Use interactive password prompts or database-specific protected credential stores.
  • For PostgreSQL, use a properly permissioned password file or other supported secret provider.
  • For MySQL, use a protected login path or configuration file rather than a command-line password.
  • For Redis, use a protected configuration or secret-loading mechanism instead of -a.
  • If environment variables are used, avoid printing them and document that some environments may expose process environments to privileged local users.
  • Add an explicit warning that quoting credentials does not keep them out of history or process listings.
  • Recommend least-privileged, short-lived database credentials and credential rotation following accidental exposure.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:121
Finding

Database Exports Written to Predictable Shared Temporary Files

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 121–130 and 268–269
Vulnerability Type: Unsafe temporary-file handling
Risk Level: Medium

Vulnerable Code

bash
# CSV (PostgreSQL)
psql "$CONN" -c "\copy (SELECT * FROM table_name) TO '/tmp/export.csv' WITH CSV HEADER"

# CSV (MySQL)
mysql "$CONN" -e "SELECT * FROM table_name" | sed 's/\t/,/g' > /tmp/export.csv

# JSON (PostgreSQL)
psql "$CONN" -t -c "SELECT json_agg(t) FROM (SELECT * FROM table_name LIMIT 100) t;" > /tmp/export.json

# SQLite to CSV
sqlite3 /path/to/db.db ".mode csv" ".headers on" ".output /tmp/export.csv" "SELECT * FROM table_name;" ".quit"
bash
# PostgreSQL to CSV to MySQL
psql "$PG_CONN" -c "\copy table_name TO '/tmp/export.csv' WITH CSV HEADER"
mysql "$MYSQL_CONN" -e "LOAD DATA LOCAL INFILE '/tmp/export.csv' INTO TABLE table_name FIELDS TERMINATED BY ',' ENCLOSED BY '\"' LINES TERMINATED BY '\n' IGNORE 1 ROWS;"

Technical Analysis

The instructions write database records to fixed, predictable paths in the shared /tmp directory. They do not establish a restrictive umask, create a private temporary directory, verify file ownership, reject symbolic links, or remove the exported data afterward.

On a multi-user system, another local account can predict these paths and monitor or read files if their permissions permit it. For shell-created output files, an attacker may also prepare a symbolic link at the expected path, potentially redirecting output to another file writable by the victim. Reusing one path for different exports can additionally overwrite or mix unrelated sensitive datasets.

Attack Path

  1. A local attacker predicts that an export will use /tmp/export.csv or /tmp/export.json.
  2. The attacker monitors the path for file creation or, where applicable, creates a symbolic link at the expected location.
  3. A user follows the documented command and exports database contents.
  4. T ...[truncated 828 chars]
Remediation
View remediation

Remediation Suggestions

  • Create a private temporary directory with mktemp -d rather than using fixed names directly under /tmp.
  • Set umask 077 before creating files containing database data.
  • Generate unique export filenames and verify that the destination is owned by the current user.
  • Use file-creation methods that fail if the destination already exists and do not follow symbolic links.
  • Allow the user to choose and confirm the final export destination.
  • Add cleanup logic, such as a shell trap, to delete temporary exports when processing completes.
  • Apply restrictive permissions to exports that must be retained.
  • Avoid unrestricted SELECT * exports by default; select only required columns and enforce a bounded result set unless the user explicitly confirms a full export.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:70
Finding

Unbounded Redis Key Enumeration Can Block Production Instances

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 70
Vulnerability Type: Unbounded blocking database operation
Risk Level: Low

Vulnerable Code

bash
redis-cli -h host -p 6379 -a password KEYS "*"

Technical Analysis

Redis processes KEYS "*" by traversing the complete selected keyspace. Because Redis command processing is primarily single-threaded, executing this operation against a large production dataset can occupy the server and delay unrelated client requests.

Unlike cursor-based iteration, this command has no natural pagination or bounded result count. Its use also conflicts with the skill's general requirement to limit query results.

Attack Path

  1. A user or agent follows the exploration example against a production Redis instance.
  2. The selected Redis database contains a large number of keys.
  3. KEYS "*" synchronously traverses the entire keyspace and returns every matching key.
  4. Other Redis client operations are delayed while the enumeration is processed.
  5. Application latency increases and dependent services may experience timeouts or temporary unavailability.

Impact Assessment

Exploitation can degrade the availability and responsiveness of the targeted Redis instance and applications that depend on it. The effect is limited to instances accessible with the supplied account and network connection, but may affect all tenants or services sharing that Redis deployment.

This issue does not provide additional privileges or direct data modification. It can, however, enumerate key names and cause a temporary denial-of-service condition on sufficiently large datasets.

Remediation
View remediation

Remediation Suggestions

  • Replace KEYS "*" with cursor-based SCAN.
  • Use a conservative COUNT value and stop after a bounded number of results during routine exploration.
  • Apply a narrow MATCH pattern whenever the relevant key prefix is known.
  • Require explicit user confirmation before conducting a complete keyspace traversal.
  • Warn users not to run blocking enumeration commands against production instances.
  • Prefer replicas or dedicated diagnostic environments for large-scale inventory operations.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Trigger phrases like 'check the database' or 'show me the data' are broad and likely to overlap with ordinary conversation, causing unintended skill activation. Because this skill can access databases and includes operational commands beyond read-only inspection, accidental activation raises the risk of exposing sensitive data or steering the agent into unsafe database actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The safety section says write operations require confirmation, but later examples provide restore and import commands in directly executable form without any embedded confirmation procedure. This inconsistency is dangerous because an agent or user may treat the examples as approved defaults and execute data-destructive operations without an explicit approval checkpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation covers export, backup, restore, and migration operations but does not present prominent, repeated warnings about data loss, credential exposure, environment targeting, and production impact near those commands. In a high-risk context like database administration, omission of strong guardrails materially increases the chance of confidentiality breaches, corruption, or service disruption.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill's stated purpose is database exploration/querying, but it also includes restore, dump, and migration procedures that can directly modify or overwrite production data. In an agent setting, this broadens the operational scope from read-oriented inspection to destructive administrative actions, increasing the chance of accidental execution or misuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.