Back to skill

Security audit

Text2sql Engine

Security checks for vulnerabilities and agentic risk

Overview

This SQL helper is not proven malicious, but it asks for broad command, file-write, and database authority without enough scoping or consent safeguards.

Review this before installing in any environment with real databases or sensitive files. Use a read-only database account, avoid sharing production credentials, require explicit approval before executing SQL, writing files, calling APIs, or running commands, and do not follow the administrator-elevation advice as a generic fix.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:28
Finding

Excessive Agent Capabilities and Unsafe Privilege-Elevation Guidance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

For an NL2SQL skill, broad file handling, API integration, and system command execution materially exceed the minimum privileges needed to translate natural language into SQL. If invoked by an agent, these capabilities could be abused to read sensitive files, modify artifacts, call external services, or execute host commands unrelated to the stated purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation language is so broad that it encourages use for nearly any database operation or data management task, not just SQL generation. Overbroad triggering increases the chance that an agent will invoke the skill in higher-risk contexts, including tasks involving production data, schema changes, or sensitive database actions beyond safe advisory use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description explicitly states '支持中文交互' and presents the skill as operating in Chinese, while the display name and surrounding content also center a fixed locale. There is no indication that users may choose another language or that the Chinese-only behavior is an intentional, documented regional constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill states that index recommendations are not automatically executed, but the declared exec and write capabilities make it technically possible for an agent to apply DDL changes anyway. This mismatch can mislead users and downstream agents into trusting the skill as read-only or advisory when it can actually modify database state or local files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises file writes, API access, and command execution without prominently warning users that these actions can change system state, expose data externally, or run host-level operations. In an agent ecosystem, missing warnings and consent boundaries increase the likelihood of unsafe autonomous execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.