Back to skill

Security audit

database-agent

Security checks for vulnerabilities and agentic risk

Overview

This database helper includes raw SQL execution paths that can read or change a database without enforcing the safety checks its documentation promises.

Review this skill carefully before installing. Use only least-privilege database accounts, preferably read-only for analysis, and do not let it execute or generate production data changes without separate human review, tested backups, rollback plans, and transaction controls. Treat generated SQL and Excel reports as untrusted outputs that need review before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/database_connector.py:95
Finding

Unrestricted Database Statements Bypass Advertised Safety Controls

Content
View full analysis
int: """ Execute an UPDATE/INSERT/DELETE statement. Args: sql: SQL statement params: Statement parameters Returns: Number of affected rows """ if not self.connection: raise RuntimeError("Not connected to database") with self.connection.cursor() as cursor: affected_rows = cursor.execute(sql, params) self.connection.commit() return affected_rows ``` ```python def explain_query(self, sql: str) -> str: """Get execution plan for a query.""" db_type = self.config.get('type', 'mysql') if db_type == 'mysql': explain_sql = f"EXPLAIN {sql}" elif db_type == 'postgresql': explain_sql = f"EXPLAIN ANALYZE {sql}" result = self.execute_query(explain_sql) return json.dumps(result, indent=2) ``` ```python elif args.action == 'query': if not args.sql: print("Error: --sql required for query action") return result = connector.execute_query(args.sql) print(json.dumps(result, indent=2)) elif args.action == 'explain': if not args.sql: print("Error: --sql required for explain action") return plan = connector.explain_query(args.sql) print(plan) ``` ### Technical Analysis The connector accepts arbitrary SQL without parsing or restricting its statement type. It does not enforce a single-statement policy, a read-only transaction, an affected-row threshold, user confirmation, or the separate `DataCorrectionValidator`. The `execute_update` method commits immediately after executing caller-supplied SQL. This defeats the Skill's documented requirements to validate modifications, create a b ...[truncated 1731 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/validate_data_correction.py:54
Finding

Regex-Based SQL Validation Is Bypassable and Produces Unreliable Recovery SQL

Content
View full analysis
str: """Determine the type of SQL operation.""" if 'UPDATE' in sql_upper: return 'UPDATE' elif 'DELETE' in sql_upper: return 'DELETE' elif 'INSERT' in sql_upper: return 'INSERT' return 'UNKNOWN' def _check_where_clause(self, sql: str, operation: str): """Check for missing WHERE clause.""" if operation in ['UPDATE', 'DELETE']: if not re.search(r'\bWHERE\b', sql, re.IGNORECASE): self.risks.append({ 'type': 'MISSING_WHERE', 'severity': 'CRITICAL', 'message': f'{operation} without WHERE clause affects entire table', 'recommendation': 'Add WHERE clause to limit affected rows' }) self.is_safe = False ``` ```python def generate_backup_sql(self, sql: str, table_name: str = None) -> str: """Generate backup SQL statement.""" # Extract table name from SQL if not provided if not table_name: table_match = re.search(r'\bFROM\s+(\w+)', sql, re.IGNORECASE) if table_match: table_name = table_match.group(1) else: table_name = 'unknown_table' # Extract WHERE clause where_match = re.search(r'\bWHERE\s+(.+)', sql, re.IGNORECASE) where_clause = where_match.group(1) if where_match else '1=1' # Generate backup table name timestamp = datetime.now().strftime('%Y%m%d_%H%M%S') backup_table = f"{table_name}_backup_{timestamp}" return f"CREATE TABLE {backup_table} AS SELECT * FROM {table_name} WHERE {where_clause};" def generate_rollback_sql(self, sql: str, table_name: str = None) -> List[str]: """Generate rollback SQL statements.""" ...[truncated 3542 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_test_data.py:166
Finding

Generated SQL Interpolates Untrusted Table and Column Identifiers

Content
View full analysis
List[str]: """Generate INSERT SQL statements from test data.""" statements = [] for row in rows: columns = ', '.join(row.keys()) values = [] for value in row.values(): if value is None: values.append('NULL') elif isinstance(value, str): # Escape quotes escaped = value.replace("'", "''") values.append(f"'{escaped}'") elif isinstance(value, (int, float)): values.append(str(value)) else: values.append(f"'{value}'") values_str = ', '.join(values) sql = f"INSERT INTO {table_name} ({columns}) VALUES ({values_str});" statements.append(sql) return statements ``` ```python def generate_batch_insert(self, table_name: str, rows: List[Dict], batch_size: int = 100) -> List[str]: """Generate batch INSERT statements for better performance.""" statements = [] for i in range(0, len(rows), batch_size): batch = rows[i:i + batch_size] if not batch: continue columns = ', '.join(batch[0].keys()) all_values = [] for row in batch: values = [] for value in row.values(): if value is None: values.append('NULL') elif isinstance(value, str): escaped = value.replace("'", "''") values.append(f"'{escaped}'") elif isinstance(value, (int, float)): valu ...[truncated 3349 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_report.py:50
Finding

Excel Reports Permit Spreadsheet Formula Injection

Content
View full analysis
= 80 else 'FAIL' ws_summary.append([ result.get('table_name', ''), score, violations_count, warnings_count, status ]) ``` ```python for result in results: table_name = result.get('table_name', '') for violation in result.get('violations', []): ws_details.append([ table_name, violation.get('type', ''), violation.get('severity', ''), violation.get('message', ''), violation.get('suggestion', '') ]) for warning in result.get('warnings', []): ws_details.append([ table_name, warning.get('type', ''), warning.get('severity', ''), warning.get('message', ''), warning.get('suggestion', '') ]) ``` ```python for result in results: sql = result.get('sql', '') severity = result.get('severity', '') for issue in result.get('issues', []): ws.append([ sql[:100] + '...' if len(sql) > 100 else sql, issue.get('severity', ''), issue.get('type', ''), issue.get('message', ''), '' # Recommendations in separate column ]) ``` ### Technical Analysis The report generator writes input-derived table names, SQL text, issue types, messages, and suggestions directly into XLSX cells. Spreadsheet applications can interpret strings beginning with characters such as `=`, `+`, `-`, or `@` as ...[truncated 1605 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If the underlying skill can execute arbitrary database queries and updates through a generic connector while presenting itself as a narrowly scoped helper, that creates a significant privilege and expectation mismatch. In a database-oriented skill, undocumented write/query execution is especially dangerous because it could enable unauthorized data access, modification, or destructive operations under the guise of analysis tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the underlying skill can execute arbitrary database queries and updates through a generic connector while presenting itself as a narrowly scoped helper, that creates a significant privilege and expectation mismatch. In a database-oriented skill, undocumented write/query execution is especially dangerous because it could enable unauthorized data access, modification, or destructive operations under the guise of analysis tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the underlying skill can execute arbitrary database queries and updates through a generic connector while presenting itself as a narrowly scoped helper, that creates a significant privilege and expectation mismatch. In a database-oriented skill, undocumented write/query execution is especially dangerous because it could enable unauthorized data access, modification, or destructive operations under the guise of analysis tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the underlying skill can execute arbitrary database queries and updates through a generic connector while presenting itself as a narrowly scoped helper, that creates a significant privilege and expectation mismatch. In a database-oriented skill, undocumented write/query execution is especially dangerous because it could enable unauthorized data access, modification, or destructive operations under the guise of analysis tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the underlying skill can execute arbitrary database queries and updates through a generic connector while presenting itself as a narrowly scoped helper, that creates a significant privilege and expectation mismatch. In a database-oriented skill, undocumented write/query execution is especially dangerous because it could enable unauthorized data access, modification, or destructive operations under the guise of analysis tasks.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/database_connector.py (reported line 97)May include surrounding context.

python
def execute_update(self, sql: str, params: tuple = None) -> int:
        """
        Execute an UPDATE/INSERT/DELETE statement.
        
        Args:
            sql: SQL statement

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly encourages generating test data using 'real data' for test environments without any warning about privacy, masking, consent, or regulatory constraints. In a database skill, this context makes the issue more dangerous because it normalizes copying production-like personal or sensitive data into lower-trust environments, increasing the risk of data leakage and compliance violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON config includes only Chinese names, cities, districts, and street formats, which imposes a specific locale in natural-language data generation. Under the policy, locale-specific behavior should either offer user choice or be explicitly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file includes natural-language and data-format guidance that defaults to Chinese phone numbering, later reinforced by Chinese names, addresses, text strings, and a fixed 'CNY' currency value. Because the document presents itself as general test-data guidance rather than a clearly region-specific standard, these locale choices appear imposed without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes schema validation and database-operation assistance, but this file is documented and structured as a compliance checker that validates table structures. Despite that read/analysis-oriented role, it also includes logic to generate ALTER TABLE statements that would modify schema, which is a broader behavior than pure compliance checking.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module exposes a generic SQL execution primitive via execute_query/execute_update that will run arbitrary caller-supplied statements against the configured database. In the context of an agent skill, this broad capability exceeds a narrowly scoped analysis/repair helper and increases the risk of misuse, prompt-driven dangerous actions, or unintended access/modification of sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

execute_update commits changes immediately after executing the supplied statement, with no confirmation, dry-run, rollback guard, or policy checks. That makes accidental or prompt-induced destructive writes harder to stop and increases the blast radius of mistakes in a database-oriented automation skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI query action accepts raw user-supplied SQL and executes it directly, turning the skill into a general-purpose SQL runner. In an agent setting, that materially raises the danger because any upstream prompt or user input can trigger unrestricted reads of sensitive tables or invoke database-side dangerous functionality if permissions allow it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generator produces default names and addresses in Chinese, and later emits additional Chinese text strings for VARCHAR/TEXT fields. This enforces a specific locale in generated output without any user opt-in or documented regional scope, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default generated VARCHAR and TEXT values are written in Chinese only, with no mechanism for the user to select another language or confirm the locale assumption. Because this file is code and the policy applies to natural-language literals in code, this is a language-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON manifest contains hard-coded natural-language messages such as "Table lacks primary key" and "Critical field should be NOT NULL" with no indication that alternate languages or locale selection are supported. Because SQP-3 applies to all file types and covers language/locale policy violations, fixed English-only user-facing text can violate policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Line L259 uses currency VARCHAR(3) NOT NULL DEFAULT 'CNY' as the example of a 'meaningful default'. In a general database standards document, this effectively favors a specific locale/currency without stating that the standard is region-specific or offering alternatives, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This code constructs ALTER TABLE statements that would modify database schema if later executed. Although the function only generates SQL and does not run it, there is no inline warning or comment indicating that the output is a potentially destructive schema change.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes database-focused assistance such as slow SQL analysis, schema compliance inspection, safe data correction, and test data generation. This file implements a generic Excel report generator CLI that reads JSON from disk and writes spreadsheet files, which is auxiliary reporting functionality not stated in the skill purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.