Back to skill

Security audit

Sql Query

Security checks for vulnerabilities and agentic risk

Overview

This SQL skill is not overtly malicious, but it asks for broad command and file access for sensitive database work without enough scoping or user-control detail.

Review this skill before installing. Use it only in a sandbox or least-privileged workspace, with least-privileged database accounts, explicit approval for write queries and external webhooks, pinned dependencies, and clear limits on which files and commands the agent may access.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:202
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 202-203
Vulnerability Type: Unpinned and unverifiable third-party dependencies
Risk Level: Medium

Vulnerable Code

markdown
| redis | Python package | Optional | `pip install redis` (distributed cache) |
| psycopg2 | Python package | Optional | `pip install psycopg2` (database driver) |

Technical Analysis

The installation instructions do not pin reviewed package versions or verify package integrity with cryptographic hashes. As a result, the installed artifacts can change over time even when the Skill itself remains unchanged.

Python package installation may execute package-controlled build or installation logic. If the configured package index, a dependency, or a future package release is compromised, following these commands could execute unreviewed code with the privileges of the user running pip. The absence of a lock file or hash-verified requirements also prevents reproducible dependency resolution.

The audited repository does not contain evidence that either named package is currently malicious. The finding concerns the unsafe dependency acquisition process rather than a confirmed malicious package.

Attack Path

  1. A user follows the dependency instructions in SKILL.md.
  2. pip resolves the latest compatible package and transitive dependencies from its configured package index.
  3. An attacker compromises a resolved release, dependency, package index, or improperly configured alternative index.
  4. The malicious distribution is downloaded without a version or integrity constraint.
  5. Package-controlled installation or runtime code executes locally.
  6. The code receives the permissions of the account or environment running the installation or importing the package.

Impact Assessment

Successful supply-chain exploitation could permit arbitrary code execution within the installation environment. The attacker could a ...[truncated 454 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace ad hoc installation commands with a reviewed dependency manifest containing exact versions.
  2. Generate and verify cryptographic hashes for every direct and transitive dependency, such as by using pip install --require-hashes -r requirements.txt.
  3. Use a lock file or constraints file to make dependency resolution reproducible.
  4. Explicitly document and restrict the trusted package index; disable unintended fallback to public or alternate indexes.
  5. Install dependencies inside a dedicated virtual environment or container without administrative privileges.
  6. Scan dependency artifacts and monitor pinned versions for published vulnerabilities.
  7. Review whether psycopg2 requires local compilation and document a controlled build process appropriate to the deployment environment.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:28
Finding

Overly Broad Tool Permissions for a Documentation-Based SQL Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 28-31; related capability declarations at lines 311-313
Vulnerability Type: Excessive filesystem and command-execution permissions
Risk Level: Medium

Vulnerable Code

yaml
tools:
- read
- exec
- write

Related broad capability declarations include:

markdown
- **File processing**: Supports reading, parsing, and writing multiple file formats
- **API integration**: Calls external services through standardized interfaces and processes responses
- **Command execution**: Executes system commands in a secure sandbox and collects results

Technical Analysis

The Skill requests generic filesystem read, filesystem write, and command-execution tools even though the repository contains only documentation and no implementation that constrains their use. The permissions are not limited to designated workspace paths, approved database clients, read-only SQL operations, or an explicit command allowlist.

Granting unrestricted exec, read, and write capabilities violates least-privilege principles. If user-controlled instructions, SQL content, file paths, or database output influence subsequent tool calls, the agent could be induced to access unrelated files or execute commands outside the legitimate SQL-querying task.

The document states that command execution occurs in a secure sandbox, but the repository does not define or enforce such sandboxing. No confirmed exploitation logic, command injection payload, or malicious command is present in the audited file; the risk arises from unnecessary and unconstrained authority.

Attack Path

  1. The Skill is loaded with generic read, write, and exec permissions.
  2. A user supplies a crafted SQL-related request, file path, database value, or instruction containing an operation outside the intended task.
  3. Because the Skill defines no command allowlist or path restrictions, the age ...[truncated 1121 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove exec and write unless a documented and implemented workflow requires them.
  2. Prefer a dedicated database-query tool over a general-purpose shell.
  3. If command execution is necessary, allowlist specific database client binaries and reject shell metacharacters, command substitution, pipelines, and unapproved arguments.
  4. Restrict filesystem access to explicit workspace directories and use read-only mounts wherever possible.
  5. Run database operations under a dedicated, non-administrative operating-system account and a least-privileged database role.
  6. Require user confirmation before executing write queries, changing files, making outbound requests, or accessing paths outside the current project.
  7. Enforce outbound-network destination allowlists, particularly for alert webhooks.
  8. Define the claimed sandbox controls in enforceable configuration rather than relying on descriptive text.
  9. Prevent database content and user-supplied SQL from being interpreted as agent instructions or shell commands.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance is overly broad, suggesting use whenever database operations or related tasks are needed, without tightly constraining when high-risk capabilities should be engaged. Broad triggers increase the chance this skill is auto-selected in contexts where shell access, file writes, or sensitive data handling are unnecessary, expanding exposure and the likelihood of unsafe execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

General file write access is broader than what is necessary for a SQL query skill and can be abused to alter configuration, drop scripts, overwrite project files, or stage further compromise. Because the skill is framed as a database utility, users and agents may underestimate that it can modify the local filesystem, creating a dangerous trust mismatch.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill presents itself as a database-scoped query tool with controlled read/write routing, but its declared capabilities are unrestricted read/exec/write tools rather than a constrained database interface. That mismatch is dangerous because an agent may invoke this skill expecting bounded SQL behavior while actually granting shell and filesystem access, enabling unintended system commands, local data access, or writes far outside database operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill openly advertises file processing, external service integration, and command execution, but does not provide proportional warnings about local data exposure, outbound data transmission, credential handling, or system-side effects. In practice, this can cause users or agents to send sensitive SQL results, logs, or files to external endpoints or execute commands without informed consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

General file write access is broader than what is necessary for a SQL query skill and can be abused to alter configuration, drop scripts, overwrite project files, or stage further compromise. Because the skill is framed as a database utility, users and agents may underestimate that it can modify the local filesystem, creating a dangerous trust mismatch.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.