Back to skill

Security audit

Dolphindb Init

Security checks for vulnerabilities and agentic risk

Overview

This DolphinDB setup skill has a legitimate purpose, but it can automatically install an unpinned package into local Python environments and uses unsafe shell eval during environment loading.

Review before installing. Use this only if you are comfortable with it scanning local Python environments, and do not let it run setup automatically unless you approve the target interpreter. Prefer changing it to detection-only by default, removing eval-based loading, installing a pinned DolphinDB SDK into a dedicated virtual environment, and avoiding hardcoded database credentials in examples or scripts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/load_dolphindb_env.sh:9
Finding

Shell Command Injection Through Evaluation of Unsafely Serialized Environment Data

Content
View full analysis
/dev/null)" ``` `scripts/detect_dolphindb_env.sh:12-14`: ```bash while IFS= read -r line; do ENV_NAME=$(echo "$line" | awk '{print $1}') ENV_PATH=$(echo "$line" | awk '{print $NF}') ``` `scripts/detect_dolphindb_env.sh:83-86`: ```bash echo "export DOLPHINDB_PYTHON_BIN=\"$DOLPHINDB_PYTHON\"" echo "export DOLPHINDB_SDK_VERSION=\"$DOLPHINDB_VERSION\"" echo "export DOLPHINDB_PYTHON_VER=\"$PYTHON_VER\"" echo "export DOLPHINDB_ENV_PATH=\"$ENV_PATH\"" ``` ### Technical Analysis The loader executes all standard output generated by `detect_dolphindb_env.sh` as shell source through `eval`. The detector constructs that output by interpolating values obtained from Conda environment records and executable output into double-quoted shell assignments. Double quotes around the emitted values do not provide safe serialization. A value containing a double quote, command substitution, semicolon, newline, or another shell metacharacter can alter the generated assignment. When the loader subsequently passes the generated text to `eval`, the shell parses those characters as executable syntax. For example, a literal path component containing `$(command)` can be emitted inside the generated assignment. The command substitution is not executed during ordinary variable expansion in the detector, but it becomes active shell syntax during the second parse performed by `eval`. The same unsafe serialization pattern affects the Python path, SDK version, Python vers ...[truncated 1347 chars]
Remediation
View remediation
/dev/null`, because doing so can conceal malformed output and complicate incident diagnosis. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/detect_dolphindb_env.sh:88
Finding

Automatic Installation of an Unpinned Package into Shared Python Environments

Content
View full analysis
&1 | awk '{print $2}') if [[ "$PY_VER" == 3.13* ]]; then TARGET_PYTHON="$PY_BIN" break fi fi done # 如果没有 3.13,用系统 python3 if [ -z "$TARGET_PYTHON" ]; then for PY_BIN in /usr/local/bin/python3 /usr/bin/python3; do if [ -x "$PY_BIN" ]; then TARGET_PYTHON="$PY_BIN" break fi done fi if [ -z "$TARGET_PYTHON" ]; then echo "echo \"❌ 未找到可用的 Python\"" >&2 exit 1 fi # 安装 dolphindb $TARGET_PYTHON -m pip install dolphindb --quiet 2>/dev/null DOLPHINDB_VERSION=$($TARGET_PYTHON -m pip list 2>/dev/null | grep -i "^dolphindb" | awk '{print $2}') PYTHON_VER=$($TARGET_PYTHON --version 2>&1 | awk '{print $2}') echo "export DOLPHINDB_PYTHON_BIN=\"$TARGET_PYTHON\"" echo "export DOLPHINDB_SDK_VERSION=\"$DOLPHINDB_VERSION\"" echo "export DOLPHINDB_PYTHON_VER=\"$PYTHON_VER\"" echo "export DOLPHINDB_ENV_PATH=\"newly_installed\"" fi ``` `scripts/find_dolphindb_env.sh:175-185`: ```bash if [ -z "$TARGET_PYTHON" ]; then echo " ❌ 未找到可用的 Python" exit 1 fi echo " 安装 dolphindb 到:\$$TARGET_VAR" $TARGET_PYTHON -m pip install dolphindb --quiet DOLPHINDB_VERSION=$($TARGET_PYTHON -m pip list 2>/dev/null | grep -i "^dolphindb" | awk '{print $2}') DOLPHINDB_PYTHON="$TAR ...[truncated 2351 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description states that if a suitable environment is not found, it will automatically install the DolphinDB SDK, but it does not clearly warn that this modifies the local system. In an agent setting, silent package installation is security-relevant because it changes execution environments, introduces supply-chain risk, and may occur without informed user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger condition is overly broad, using terms like '任何时候' and '任何 DolphinDB 请求', which can cause the agent to invoke this skill for incidental mentions rather than explicit operational requests. Because this skill can inspect local Python environments and may auto-install packages, accidental activation can lead to unnecessary environment probing or system modification without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script silently installs the dolphindb package with pip install --quiet when no existing environment is found, without any user confirmation or clear disclosure. In an initialization skill that is expected to be run automatically as a prerequisite, this can unexpectedly modify the host environment, pull code from a package index, and create supply-chain and integrity risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script is presented as an environment detector/initializer, but it also performs package installation when DolphinDB is absent. That hidden state-changing behavior can unexpectedly modify a user's Python environment, pull code from package indexes, and violate least surprise for a discovery script.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script claims a privacy-preserving mode, but it still consumes concrete filesystem paths from conda environment listings and exports them into variables. That mismatch is dangerous because it can mislead users or downstream tooling into believing path exposure has been minimized when the script still performs sensitive local discovery and may reveal those paths indirectly through environment state or logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script runs pip install dolphindb automatically without explicit confirmation, causing silent modification of whichever Python interpreter it selected. In an agent skill context, that is more dangerous because the skill may be invoked as a prerequisite step, leading to unreviewed package installation and supply-chain exposure on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script uses eval on the stdout of another shell script, which means any unexpected or malicious content emitted by detect_dolphindb_env.sh will be executed in the current shell context. Because this skill is a prerequisite initializer that users are expected to run before all DolphinDB operations, compromising the detector or its output would provide a strong execution primitive and make downstream trust assumptions unsafe.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The example shows hardcoded database credentials in sample code without any caution about secret handling. Even though the values appear illustrative, this pattern can normalize embedding credentials in scripts, increasing the risk of leaking real secrets through logs, shell history, source control, or reused templates.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file includes Chinese-only natural-language comments such as 输出可直接 eval 的 export 语句, without offering any language choice or indicating that the skill is intentionally region-specific. This can violate a language/locale policy when organizational guidance expects neutral or user-selectable language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script enumerates local Conda and system Python environments and inspects installed packages via pip list without any user-facing disclosure. While this is lower severity than code execution, it reveals local software inventory and environment layout, which may expose sensitive metadata and exceeds least-surprise expectations for a setup helper.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script's comments and all user-visible status messages are in Chinese, which imposes a specific language on users regardless of their locale. Under the stated policy, language constraints should be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The script enumerates conda and system Python environments and queries installed packages across them, which is broader host inspection than strictly necessary for minimal setup. While likely intended to locate a usable DolphinDB SDK, this behavior exposes local environment inventory and increases privacy and reconnaissance risk if used in a broader agent workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file contains user-facing natural-language comments and messages in Chinese without indicating language choice or a documented locale-specific constraint. Under the stated policy, forcing a specific language without opt-in can be a locale-policy violation unless the regional limitation is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.