Back to skill

Security audit

Phpmyadmin Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about running phpMyAdmin locally, but it should be reviewed because it enables database admin access with a predictable default root password.

Install only for local development. Before starting it, set a strong unique MYSQL_ROOT_PASSWORD and confirm the connected MySQL container is not using secret. Keep the phpMyAdmin port bound to localhost, restrict access to the shared Docker network, and stop the container when it is not needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
docker-compose.yml:8
Finding

Predictable Default MySQL Root Credential

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
84% confidence
Finding

The trigger "start phpmyadmin" begins with a common built-in verb and may be parsed or matched in ways that conflict with generic start commands. This can cause the skill to intercept user intent unexpectedly and launch a Dockerized admin interface that exposes database management functionality on the host.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
82% confidence
Finding

The trigger "stop phpmyadmin" similarly overlaps with generic stop semantics and may capture unrelated user commands. While the impact is lower than unintended startup, accidental shutdown of an admin container can disrupt local workflows or interfere with other dependent development tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases "interface mysql" and "admin mysql" are broad enough that they could be invoked during normal conversation or overlap with unrelated requests about MySQL administration. In an agent that can start or expose local infrastructure, ambiguous activation increases the chance of unintended container actions and unwanted service exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger list includes the Spanish-only phrase "abrir phpmyadmin" alongside English triggers, but the file does not explain language selection or indicate whether multilingual triggering is intentional and user-driven. This can create a locale-policy issue if the skill behavior depends on language choices that are not explicitly offered or documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script's documentation and runtime messages are written in Portuguese only, which imposes a specific language on users without any opt-in or alternative. The policy allows locale constraints only when explicitly justified or when users are given a choice, neither of which is present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.