Back to skill

Security audit

sql-free

Security checks for vulnerabilities and agentic risk

Overview

This SQL helper is not clearly malicious, but it asks for broad command/file authority and includes an unrestricted callback URL that could expose database-related information.

Review before installing. Use this only with non-sensitive schemas or sanitized examples unless you can control callback behavior and confirm every command, file write, and database execution step. Do not provide database passwords, production query results, or confidential business data to this skill.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:39
Finding

Unrestricted Callback URL May Expose Sensitive Database Information

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39–45
Vulnerability Type: User-controlled outbound callback destination
Risk Level: High

Vulnerable Code

markdown
## Input Definition
| Parameter | Type | Required | Description |
|---|---|---|---|
| input | string | Yes | Input data or instructions processed by the SQL assistant |
| options | object | No | Additional configuration, such as mode or format preferences |
| callback_url | string | No | Callback URL notified after asynchronous processing |

The underlying declaration defines callback_url as an unrestricted string and does not specify any destination or payload security controls.

Technical Analysis

The Skill accepts a user-controlled callback URL for asynchronous result delivery. No requirements are provided for HTTPS enforcement, trusted-origin allowlisting, redirect handling, DNS rebinding protection, private-address rejection, callback authentication, or outbound payload filtering.

SQL-assistance inputs and outputs can contain sensitive material, including table schemas, column names, SQL statements, business identifiers, query plans, and potentially query results. Sending such output to an arbitrary callback destination can disclose this information to an attacker-controlled server.

The callback can also create a server-side request forgery condition if the execution environment honors the documented parameter without additional validation. An attacker could supply a loopback, private-network, link-local, or cloud metadata address and cause the Agent to issue a request to a service that is not directly accessible to the attacker.

The risk is amplified by the Skill's broad read, exec, and write tool declarations and its generic API-integration capability. However, the audited file does not contain a concrete command that directly reads credentials or transmits an API key.

Attack Path

  1. An attacker or un ...[truncated 1298 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove callback functionality if asynchronous outbound delivery is not essential to the declared SQL-assistance functionality.
  2. Require explicit, informed user confirmation before transmitting SQL, schemas, query plans, or database results to any external endpoint.
  3. Restrict destinations to a configured allowlist of trusted HTTPS origins. Do not accept arbitrary URLs directly from task input.
  4. Reject loopback, private, link-local, multicast, and reserved IP ranges after DNS resolution, including IPv4 and IPv6 representations.
  5. Revalidate the destination after every redirect and either disable redirects or restrict them to the same approved origin.
  6. Protect against DNS rebinding by resolving and validating addresses at connection time.
  7. Define a minimal callback schema and exclude raw input, credentials, connection strings, complete schemas, and query results by default.
  8. Redact secrets and sensitive fields before transmission and impose payload-size limits.
  9. Authenticate callback destinations and cryptographically sign callback payloads so recipients can verify their origin and integrity.
  10. Apply strict connection and response timeouts, response-size limits, retry limits, and outbound network controls.
  11. Record callback destination, approval, payload classification, and delivery result in security audit logs without logging secrets.
  12. Remove or narrowly scope the declared exec, read, and write tools unless a specific operation requires them.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description explicitly states '不适用于数据库架构设计决策' (not suitable for database architecture design decisions). However, the body of the skill documentation later claims capabilities for '数据库Schema设计', including table structure design, index strategy, ER diagram generation, and migration scripts, which are architecture/design activities.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

At the top-level description, the skill says it is not applicable to database architecture design decisions. Later documentation claims the skill supports schema design, index strategy, ER generation, and DDL/migration generation, which directly conflicts with that stated limitation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to use the skill whenever database operations, SQL queries, or data storage management are needed, which is a very broad trigger scope. It does not provide concrete trigger phrases, constraints, or negative examples beyond excluding architecture decisions, so it could match many ordinary development requests and cause unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares powerful tools including exec and write, but the description near activation does not clearly warn users that invoking the skill may execute commands or modify files. In an agent environment, that omission can cause users or orchestrators to trigger the skill without informed consent, increasing the risk of unintended local command execution, file changes, or handling of sensitive database material.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.