T09 · Insecure Skill Coding Practices
- Location
scripts/init_dolphindb_env.py:24- Finding
Shell Command Injection Through Untrusted Python Interpreter Paths
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This DolphinDB skill is purpose-related but needs Review because its required setup can automatically install packages and evaluate shell output, creating persistent environment changes and command-execution risk.
Install only after reviewing the setup scripts. Use a dedicated virtual environment, disable or avoid automatic installation, pin the dolphindb package and Docker image, avoid sourcing wrappers that eval generated output until fixed, replace admin/123456 with least-privileged credentials, and require explicit confirmation before delete/drop operations, Docker deployment, or any package install.
scripts/init_dolphindb_env.py:24Shell Command Injection Through Untrusted Python Interpreter Paths
scripts/dolphin_wrapper.sh:20Arbitrary Shell Execution Through Unsafe Evaluation of Generated Export Statements
scripts/init_dolphindb_env.py:154Automatic Installation of an Unpinned Third-Party Package Into Existing Python Environments
SKILL.md:72Documentation Encourages Predictable Administrative Database Credentials
The basic skill explicitly includes delete and drop capabilities, yet the document does not warn about irreversible data loss or recommend safeguards. In this context, accidental invocation or misunderstood instructions could destroy databases, tables, or partitions.
The script is presented as a detector/export helper, but it also performs an undeclared state-changing action by installing the dolphindb package when none is found. In an agent skill context, hidden installation behavior is risky because callers may eval or invoke it expecting only discovery output, yet it modifies the host environment and pulls code from a package repository without explicit consent.
The file presents itself as an environment detector, but the later logic changes system state by selecting a Python interpreter and installing the dolphindb package. In an agent skill, this mismatch is dangerous because a seemingly read-only discovery step can unexpectedly modify the host, introduce supply-chain risk, and violate least surprise for users and orchestrators.
This markdown file is written entirely in Chinese, including operational instructions and user-facing notices, with no indication that users may choose another language. The policy explicitly flags language or locale constraints when a skill forces a specific language without user opt-in.
This markdown file presents all operational instructions, warnings, and usage guidance exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue unless the locale restriction is explicitly justified, which is not stated here.
The guide explicitly says that if no existing SDK environment is found, it will automatically install DolphinDB into a Python 3.13 environment, but it does not warn users that this modifies the local system or Python environment. In an agent skill context, undocumented package installation is risky because an automated assistant may perform persistent changes, introduce dependency conflicts, or alter a shared interpreter without informed user consent.
The troubleshooting section instructs users to run pip install dolphindb after exporting a Python interpreter, but it does not disclose that this will change that interpreter's installed packages. In a skill used by an AI agent, such instructions can lead to silent, persistent environment modification and break unrelated workflows if the selected interpreter is global or shared.
The natural-language content throughout the file forces a single language/locale presentation, and there is no indication that users can choose another language or that the Chinese-only format is required for a region-specific purpose. This matches the policy category for language or locale constraints without user opt-in.
This markdown file presents all user-facing instructions in Chinese, and there is no indication that users may choose another language or that the language restriction is intentionally limited to a specific audience. That can violate a language/locale policy requiring user choice or explicit justification for a forced language.
The documentation explicitly states that if no existing SDK is found, it will automatically install into a local Python 3.13 environment. Even though this is documentation rather than executable code, instructing an agent to modify the user's local environment without an explicit confirmation step can lead to unauthorized package installation, unexpected environment changes, and supply-chain exposure if package sources are not constrained. In this skill context, that behavior is more dangerous because the workflow is described as mandatory and automatic, which increases the chance an agent will perform system changes by default.
The document begins entirely in Chinese and provides no indication that users may choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The document advertises automatic installation support and environment detection without clearly warning that this may modify the user's system or install packages. In a skill context, users may follow these instructions and trigger unreviewed dependency installation, increasing supply-chain and integrity risks if package sources or install behavior are not tightly controlled.
The release notes instruct users to source shell wrappers and emphasize persistent environment variables, but do not warn that sourcing executes shell code in the current session and can alter PATH, variables, and command behavior. In an agent-skill ecosystem, this is more dangerous because users may trust wrapper scripts without reviewing them, enabling privilege misuse, persistence, or session tampering if the scripts are later changed or compromised.
The skill advertises database creation, modification, deletion, and automatic installation capabilities but does not clearly warn that these actions can alter data or the host environment. In an agent setting, omission of such warnings increases the risk of users authorizing destructive or system-changing operations without informed consent.
The example hardcodes admin / 123456, normalizing the use of default or weak credentials and potentially encouraging insecure deployments. If copied into real environments, this could lead to trivial unauthorized access to the database service.
The Docker deployment example starts a network-accessible container with exposed ports and persistent storage but provides no security guidance. Users may deploy an exposed service with default settings, creating attack surface for unauthorized access or misuse.
The Docker example pulls and runs dolphindb/dolphindb:latest, which is mutable and can change over time. This creates supply-chain and reproducibility risk: a future image update or registry compromise could cause users to deploy an unexpected or malicious image.
The Docker skill trigger list contains broad operational phrases like quick deployment and one-click install. This increases the chance that unrelated user requests could invoke deployment behavior, leading to unreviewed installation, container startup, or port exposure.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
#### 📖 详细文档
查看完整技能:`skills/dolphindb-docker/SKILL.md`
---
The trigger keywords for the quant-finance skill include broad terms such as strategy backtesting, query-like concepts, and common finance phrases without clear boundaries. In an agentic system, overly broad triggers can cause the skill to activate unexpectedly and perform sensitive DB or analytics actions outside the user's intended scope.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
#### 📖 详细文档
查看完整技能:`skills/dolphindb-basic/SKILL.md`
---
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
#### 📖 详细文档
查看完整技能:`skills/dolphindb-quant-finance/SKILL.md`
---
The streaming skill trigger words include generic terms like real-time computation and monitoring with no exclusion criteria. In context, this can unintentionally route ordinary analytics requests into a skill capable of standing up streaming infrastructure or modifying database state.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
#### 📖 详细文档
查看完整技能:`skills/dolphindb-streaming/SKILL.md`
---
Lines L169-L172 describe a branch where missing SDK leads to 'automatic installation'. However, the concrete example implementation at L111-L121 only reports that the SDK is not installed and terminates with sys.exit(1). This is an intent/documentation contradiction rather than mere incompleteness because the document explicitly claims an automatic remediation path.
No suspicious patterns detected.