Back to skill

Security audit

Sql Gen

Security checks for vulnerabilities and agentic risk

Overview

This SQL-generation skill is not clearly malicious, but its broad command/file/database authority is under-scoped enough that users should review it carefully before installing.

Review before installing. Use a constrained workspace, a read-only database account for schema discovery, explicit confirmation before writing migration files or executing SQL, pinned dependencies in a virtual environment, and do not run the agent as administrator just to fix permission errors.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:203
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 203-206
Vulnerability Type: Unpinned and unverifiable third-party dependencies
Risk Level: Medium

Evidence

bash
pip install psycopg2
pip install pymysql
pip install pyodbc
pip install sqlparse

Technical Analysis

The installation instructions do not pin dependency versions, require package hashes, define a trusted package index, or use a reviewed lockfile. Consequently, the packages installed can change independently of the audited Skill.

Python package installation can execute package-controlled build logic. If a configured package index is compromised, a dependency account is taken over, or dependency resolution is redirected to an untrusted index, following these instructions could execute attacker-controlled code with the privileges of the user running pip.

The document does not itself retrieve or execute a known malicious package. This finding concerns the avoidable supply-chain exposure created by mutable and unverifiable installation instructions.

Attack Path

  1. A user or Agent follows the dependency installation instructions.
  2. pip resolves the current package release using the environment's configured package indexes.
  3. An attacker compromises a listed package, its release process, or a package index used by the environment.
  4. pip downloads and processes the attacker-controlled distribution.
  5. Malicious build or installation logic executes under the invoking user's account.
  6. The payload may access files, environment variables, database credentials, and network resources available to that account.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user or Agent environment that performs the installation. The accessible scope may include project files, user-readable configuration, environment variables, database connection credentials, and wr ...[truncated 280 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin every dependency to a reviewed version rather than installing the latest available release.
  • Maintain dependencies in a lockfile and require cryptographic hashes, such as with pip install --require-hashes.
  • Explicitly configure an approved HTTPS package index and disable unintended supplemental indexes.
  • Review dependency provenance, maintainers, release history, and transitive dependencies before approval.
  • Install dependencies in a dedicated virtual environment or container using an unprivileged account.
  • Add automated vulnerability and integrity scanning for dependencies.
  • Prefer binary distributions from trusted sources where appropriate, while still validating hashes.
  • Document a controlled update process so dependency changes receive security review before deployment.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:359
Finding

Unsafe Recommendation to Run the Process with Administrator Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 359-361; duplicated at lines 381-383
Vulnerability Type: Excessive privilege recommendation
Risk Level: Low

Evidence

The relevant troubleshooting row, translated into English, states:

text
Permission denied | The current user lacks read or write permission | Check file permissions and run as administrator

Technical Analysis

The troubleshooting guidance recommends running the process as an administrator when a file permission failure occurs. Elevating the entire Agent or Skill process is broader than granting narrowly scoped access to a required project directory and violates the principle of least privilege.

The Skill requests read, execution, and write capabilities and discusses dependency installation, file generation, database access, and migration operations. Running the encompassing process with administrator privileges would cause all subsequent commands, dependencies, and generated operations to inherit elevated permissions.

This is unsafe operational guidance rather than code that automatically elevates privileges. Exploitation therefore requires a user to follow the recommendation while attacker-controlled or unsafe input, dependencies, commands, or generated artifacts are present.

Attack Path

  1. A Skill-related file operation fails because the current account lacks access.
  2. The user follows the troubleshooting recommendation and restarts the Agent, terminal, or process as an administrator.
  3. The elevated process invokes a dependency, command, generated migration, or file operation.
  4. Malicious or erroneous behavior executes with administrator privileges rather than ordinary user privileges.
  5. The operation can alter protected files or system-wide configuration accessible to the elevated account.

Impact Assessment

This recommendation can expand the impact of another defect or compromised dependency from the ...[truncated 506 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the recommendation to run the entire process as an administrator.
  • Diagnose the exact path and operation that failed before changing permissions.
  • Grant only the required read or write permission to a dedicated project or output directory.
  • Use a dedicated unprivileged service account for automation.
  • Keep dependency installation, SQL generation, and migration generation in an isolated virtual environment or container.
  • Require explicit confirmation and security review before any operation that genuinely needs elevation.
  • Provide platform-specific guidance for narrowly scoped filesystem access-control changes.
  • Add an explicit warning that Agents and generated commands must not be run with administrator privileges as a generic response to permission errors.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation explicitly advertises system command execution even though the stated purpose is natural-language-to-SQL generation. Unnecessary command execution materially increases the attack surface because prompt-driven workflows may be steered into running shell commands, touching local files, or chaining into destructive operations unrelated to SQL generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation guidance says to use the skill for broad productivity, automation, batch processing, and workflow optimization scenarios rather than a constrained SQL-specific use case. Overbroad triggers increase accidental activation in inappropriate contexts, which is especially risky here because the skill also has read/write/exec tooling and database-adjacent behaviors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The schema-aware mode is described as automatically connecting to a database and reading table structure, but the skill does not prominently warn that live schema metadata may be exposed to the agent. Even if only metadata is accessed, table names, column names, and relationships can reveal sensitive business structure and expand data-exposure risk beyond what users may expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes migration generation and uses write-enabled tooling, but it does not prominently warn that these workflows create or modify files and can facilitate database-changing actions downstream. In an agent setting, users may mistake generated migrations for harmless text output when they are actually operational artifacts that can later alter production or staging systems.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The document claims a narrow limitation around stored procedures, yet elsewhere promotes broad automation and command execution. These contradictory claims can mislead users and supervising agents about the real operational scope, making it easier for risky behaviors to be triggered under the guise of a narrowly focused SQL helper.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a focused SQL-generation tool, but its documentation also advertises broad file handling, API integration, information retrieval, and command execution capabilities. This capability sprawl weakens least-privilege expectations and can cause an agent or user to invoke the skill in contexts far beyond SQL generation, increasing the chance of unintended data access or unsafe actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.