Back to skill

Security audit

SQL大师工具(免费版)

Security checks across malware telemetry and agentic risk

Overview

This SQL helper is coherent, but it requests command execution and write access for database changes without clear safety guardrails.

Review this skill before installing if it may be used against production or shared databases. Use it only with explicit database targets, backups, and human confirmation for migrations, imports, restores, UPDATE/DELETE statements, or shell execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger condition '需要数据库操作、SQL查询、数据存储管理时使用' is very broad and can activate this skill for many generic requests involving databases or storage. Because the skill also advertises read/write/exec capabilities and operational actions like migration, backup, and restore, overbroad routing increases the chance an agent invokes it in contexts where destructive or high-risk actions were not specifically intended by the user.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill declares read/exec/write tooling and promotes backup, restore, import/export, and modification workflows, but it does not provide prominent safety constraints such as confirmation requirements, dry-run defaults, scope restrictions, or warnings about destructive operations. In an agent setting, this creates meaningful risk of unintended command execution, data alteration, overwriting files, or restoring/importing into the wrong target environment.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.