T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:28- Finding
Excessive Agent Capabilities and Unsafe Privilege-Elevation Guidance
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This SQL helper is not proven malicious, but it asks for broad command, file-write, and database authority without enough scoping or consent safeguards.
Review this before installing in any environment with real databases or sensitive files. Use a read-only database account, avoid sharing production credentials, require explicit approval before executing SQL, writing files, calling APIs, or running commands, and do not follow the administrator-elevation advice as a generic fix.
SKILL.md:28Excessive Agent Capabilities and Unsafe Privilege-Elevation Guidance
For an NL2SQL skill, broad file handling, API integration, and system command execution materially exceed the minimum privileges needed to translate natural language into SQL. If invoked by an agent, these capabilities could be abused to read sensitive files, modify artifacts, call external services, or execute host commands unrelated to the stated purpose.
The activation language is so broad that it encourages use for nearly any database operation or data management task, not just SQL generation. Overbroad triggering increases the chance that an agent will invoke the skill in higher-risk contexts, including tasks involving production data, schema changes, or sensitive database actions beyond safe advisory use.
The description explicitly states '支持中文交互' and presents the skill as operating in Chinese, while the display name and surrounding content also center a fixed locale. There is no indication that users may choose another language or that the Chinese-only behavior is an intentional, documented regional constraint.
The skill states that index recommendations are not automatically executed, but the declared exec and write capabilities make it technically possible for an agent to apply DDL changes anyway. This mismatch can mislead users and downstream agents into trusting the skill as read-only or advisory when it can actually modify database state or local files.
The skill advertises file writes, API access, and command execution without prominently warning users that these actions can change system state, expose data externally, or run host-level operations. In an agent ecosystem, missing warnings and consent boundaries increase the likelihood of unsafe autonomous execution.
No suspicious patterns detected.