Back to skill

Security audit

sql-explain

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a local SQL helper, but its install instructions can fetch executable Python from a mutable GitHub branch without verification.

Review the install path before using this skill. Prefer the bundled sql_explain.py from the reviewed package, or require a pinned commit and SHA-256 verification before running any downloaded script. Treat generated INSERT, UPDATE, and DELETE SQL as drafts for human review, not commands to execute automatically.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Warning
Location
README.md:33
Finding

Mutable Remote Python Payload Downloaded Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 33–35
Vulnerability Type: Remote payload retrieval through a mutable source
Risk Level: Medium

bash
# Or download the script directly
curl -O https://raw.githubusercontent.com/shenghoo/sql-explain/main/sql_explain.py
chmod +x sql_explain.py

Technical Analysis

The installation instructions download executable Python code from the mutable main branch of a personal GitHub repository. The command does not pin the payload to a reviewed commit, verify a cryptographic checksum, or validate a digital signature.

Consequently, the file obtained by users can differ from the version included in and reviewed as part of this Skill. Marking the downloaded file executable prepares it for direct execution. Remote retrieval is unnecessary for the declared local SQL-analysis functionality because sql_explain.py is already included in the project.

The audited bundled implementation contains no network access, command execution, persistence, credential access, or malicious payload. However, those properties cannot be guaranteed for the future remote file referenced by this mutable URL.

Attack Path

  1. An attacker compromises the GitHub account, repository, branch, or maintainer workflow associated with the remote URL.
  2. The attacker replaces sql_explain.py on the main branch with malicious Python code.
  3. A user follows the documented curl command and downloads the modified file.
  4. The user marks the file executable as instructed.
  5. The user subsequently invokes the downloaded script, directly or through Python.
  6. The malicious code executes with the privileges of the invoking user.

Impact Assessment

Successful exploitation permits arbitrary code execution under the account that launches the downloaded script. Depending on that account's permissions, an attacker could access user-readable files and environment variables, modify use ...[truncated 215 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the remote download instructions and direct users to the audited sql_explain.py distributed with the Skill.
  • If remote retrieval must remain supported, use a URL pinned to a reviewed immutable commit rather than the main branch.
  • Publish and require verification of a SHA-256 checksum or a trusted digital signature before execution.
  • Distribute versioned release artifacts through a controlled release process.
  • Avoid marking downloaded files executable unless direct execution is necessary; explicitly invoke verified files with Python.
  • Document that users should not execute a downloaded artifact if integrity verification fails.

T08 · Insecure Dependencies

Note
Location
README.md:29
Finding

Unpinned Python Dependencies Produce Non-Reproducible Installations

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 29–31 and 120–122
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Low

bash
# Install dependency
pip install sqlparse
bash
pip install pytest
pytest test_sql_explain.py -v

Technical Analysis

The documentation installs sqlparse and pytest without fixed versions or package hashes. Each installation therefore resolves to whatever compatible release the package index serves at that time, rather than to versions reviewed with this project.

Both names refer to established packages from the standard Python package ecosystem; the audit found no evidence of dependency confusion or typosquatting. Nevertheless, the absence of version and hash pinning prevents reproducible installation and expands exposure to compromised, malicious, or unexpectedly incompatible future releases. Running pytest can import installed plugins and test-time dependencies, so the testing dependency also participates in the local execution supply chain.

Attack Path

  1. A dependency release or its publication account is compromised, or a future release introduces malicious or unsafe behavior.
  2. A user follows the unpinned pip install instruction.
  3. Package resolution selects the affected release because no reviewed version or hash is required.
  4. Package installation hooks, imports, or test execution run attacker-controlled code.
  5. That code executes with the privileges of the user running pip, the application, or the test suite.

Impact Assessment

Exploitation could result in arbitrary code execution under the installing or executing user's account. Potential access includes user-readable files, environment variables, source code, and user-owned data. If users run installation or tests with elevated privileges, the impact could extend to system-level resources, although the project documentation does not instruct users to us ...[truncated 22 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin reviewed dependency versions in a requirements file or lock file.
  • Use hash checking, such as pip install --require-hashes -r requirements.txt, with hashes generated from trusted artifacts.
  • Separate runtime and development dependencies so users do not install pytest for normal operation.
  • Regularly review and update pinned versions through a controlled dependency-update process.
  • Use isolated virtual environments and avoid installing packages with administrative privileges.
  • Add automated dependency vulnerability and provenance checks to the release process.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The primary skill description is written as a Chinese-only description, and the examples further emphasize Chinese natural-language input. There is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-language audience, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The feature list explicitly states '中文自然语言转 SQL', indicating a language-specific capability. Because no alternative language handling or user choice is mentioned, this reads as a forced locale/language constraint rather than an optional, documented regional specialization.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad, generic SQL-help terms such as '分析sql' and 'explain this query', which are likely to match ordinary user requests that were not intended to invoke this specific skill. This can cause unintended routing of user queries into a tool workflow that analyzes or generates SQL, increasing the chance of inappropriate activation, unexpected behavior, or unsafe assistance around database operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code presents its description, usage text, examples, and error/help output in Chinese only. The policy allows locale constraints only when the skill offers a language choice or clearly documents a justified region-specific limitation, neither of which appears here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring names it as 'SQL Query Explain / SQL解释器' and lists analysis-oriented capabilities, which suggests an explanatory/inspection tool. However, nl_to_sql also produces INSERT, UPDATE, and DELETE statements, expanding the behavior from explanation/formatting/checking into generation of write-capable SQL.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language-to-SQL feature generates UPDATE and DELETE statements from vague prompts and returns them without any warning, confirmation step, or safety labeling. In an agent or automation context, this can facilitate unintended destructive database operations if the output is copied or automatically executed by another component.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The document presents the skill identity, triggers, and outputs in both Chinese and English, but it does not state how the response language is selected or give the user an explicit choice. Under the policy, forcing or implicitly preferring a language without user opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language strings throughout the file, including the module description, CLI help, and analysis output, are primarily in Chinese or bilingual form, which effectively imposes a language/locale on users. The file does not indicate that the skill is region-specific or provide an option to select output language, so it conflicts with the policy against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The docstring and comment describe extracting table names from SQL and specifically mention matching tables after FROM/JOIN. The actual regex patterns also match INTO and UPDATE, so the implementation covers write-statement targets in addition to the documented FROM/JOIN behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This Python file contains natural-language documentation entirely in Chinese, including the module docstring and many test descriptions, with no indication that users or maintainers may choose another language. The policy explicitly calls for flagging language or locale constraints when a specific language is effectively required without opt-in or clear regional justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.