Back to skill

Security audit

sql-doc

Security checks for vulnerabilities and agentic risk

Overview

This skill is a database reporting helper, but it handles sensitive incident-style records with broad raw queries, plaintext internal HTTP calls, and unredacted report output.

Review this skill carefully before installing. It should only be used in an environment where the database endpoint, tables, and report recipients are explicitly authorized, and it should be revised to use authenticated HTTPS, least-privilege/allowlisted queries, redaction or aggregation by default, and a user-approved protected output path. Remove or replace the embedded incident-like sample data if it could represent real records.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:15
Finding

Unencrypted Transmission of Sensitive Database Queries and Results

Content
View full analysis
LIMIT 100 OFFSET 0"}' \ "http://192.168.5.85:8000/query" ``` The mapping file also provides commands that query sensitive incident categories over the same cleartext endpoint: ```bash # 查询家庭纠纷数据 curl -X POST -H "Content-Type: application/json" -d '{"sql": "SELECT * FROM chujingxinxibiao_Sheet1_1732674000130 WHERE f_w8ZsC0='"'"'家庭纠纷'"'"'"}' "http://192.168.5.85:8000/query" # 查询婚姻纠纷数据 curl -X POST -H "Content-Type: application/json" -d '{"sql": "SELECT * FROM chujingxinxibiao_Sheet1_1732674000130 WHERE f_w8ZsC0='"'"'婚姻纠纷'"'"'"}' "http://192.168.5.85:8000/query" # 查询家暴数据 curl -X POST -H "Content-Type: application/json" -d '{"sql": "SELECT * FROM chujingxinxibiao_Sheet1_1732674000130 WHERE f_Wkv9nZ='"'"'家暴'"'"'"}' "http://192.168.5.85:8000/query" # 查询出轨数据 curl -X POST -H "Content-Type: application/json" -d '{"sql": "SELECT * FROM chujingxinxibiao_Sheet1_1732674000130 WHERE f_Wkv9nZ='"'"'出轨'"'"'"}' "http://192.168.5.85:8000/query" ``` ### Technical Analysis The documented API endpoint uses plain HTTP rather than HTTPS. Consequently, neither the SQL request nor the database response receives transport-layer confidentiality or integrity protection. The example queries target police incident information and sensitive dispute categories. Any party capable of observing or modifying traffic between the agent and `192.168.5.85:8000` could inspect the submitted SQL and returned records. An active network attacker could also modify a response, inject fabricated records, or redirect analysis toward misleading data. No API authentication or response-integrity mechanism is shown in the supplied commands. Although the address is on a private network, pri ...[truncated 1258 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
analyze_data.py:9
Finding

Sensitive Police-Incident Data Hardcoded and Exported into a Report

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
analyze_data.py:122
Finding

Sensitive Report Written to a Predictable Shared Workspace Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are broad and overlap with common user intents such as database analysis, querying data, and report generation. This increases the chance the skill will activate in contexts the user did not explicitly intend, potentially causing unauthorized querying of internal data sources or generation of reports from sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs users to perform networked database queries and generate reports but provides no warning about handling sensitive, personal, or internal data. In this context, the absence of consent, classification, and data-minimization guidance makes accidental exposure more likely, especially since the example query retrieves all columns from a table.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill explicitly sends SQL over HTTP to an internal IP-based API endpoint, creating a direct path for transmitting potentially sensitive query contents and receiving protected database records. Because the workflow is designed for data extraction and report creation, the skill context makes this more dangerous: it operationalizes bulk access to internal data without documenting authentication, encryption, access controls, or query restrictions.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

1. 查询数据

bash
curl -X POST --max-time 300 -H "Content-Type: application/json" \
  -d '{"sql": "SELECT * FROM <表名> LIMIT 100 OFFSET 0"}' \
  "http://192.168.5.85:8000/query"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script persistently writes a Word document containing raw incident records, dispute details, locations, timestamps, and sensitive identifiers embedded in the text, including what appears to be personal ID data and contact information. In this skill context, the data concerns police dispatch and domestic dispute incidents, so saving it unredacted to disk creates a real privacy and data-handling vulnerability through unauthorized local access, later exfiltration, or accidental sharing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The document contains explicit curl commands that transmit SQL statements and request sensitive law-enforcement-related data to an HTTP endpoint on an internal IP address. Using unauthenticated or unspecified controls over plain HTTP risks exposing sensitive queries and results in transit, and the embedded endpoint details may facilitate unauthorized internal access or lateral misuse.

Content

Scanner excerpt · 表名关键词映射.txt (reported line 24)May include surrounding context.

text
==========================

# 查询家庭纠纷数据
curl -X POST -H "Content-Type: application/json" -d '{"sql": "SELECT * FROM chujingxinxibiao_Sheet1_1732674000130 WHERE f_w8ZsC0='"'"'家庭纠纷'"'"'"}' "http://192.168.5.85:8000/query"

# 查询婚姻纠纷数据
curl -X POST -H "Content-Type: application/json" -d '{"sql": "SELECT * FROM chujingxinxibiao_Sheet1_1732674000130 WHERE f_w8ZsC0='"'"'婚姻纠纷'"'"'"}' "http://192.168.5.85:8000/query"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

All headings, usage instructions, and examples are presented only in Chinese, with no indication that the user can choose another language or that the file is intended solely for a Chinese-language environment. Under the stated policy, forcing a single language without opt-in can be a locale-policy issue unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file includes example SQL queries that use SELECT * against a police incident table and sends them to a query endpoint without any scope restriction, minimization, or access-control context. Because the examples target sensitive categories like domestic disputes and infidelity, they encourage broad retrieval of potentially sensitive records and could normalize over-collection or misuse of personal data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.