Back to skill

Security audit

Dolphindb Skills

Security checks for vulnerabilities and agentic risk

Overview

This DolphinDB skill is purpose-related but needs Review because its required setup can automatically install packages and evaluate shell output, creating persistent environment changes and command-execution risk.

Install only after reviewing the setup scripts. Use a dedicated virtual environment, disable or avoid automatic installation, pin the dolphindb package and Docker image, avoid sourcing wrappers that eval generated output until fixed, replace admin/123456 with least-privileged credentials, and require explicit confirmation before delete/drop operations, Docker deployment, or any package install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/init_dolphindb_env.py:24
Finding

Shell Command Injection Through Untrusted Python Interpreter Paths

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/dolphin_wrapper.sh:20
Finding

Arbitrary Shell Execution Through Unsafe Evaluation of Generated Export Statements

Content
View full analysis
/dev/null) if [ $? -eq 0 ]; then # Parse output and set environment variables while IFS= read -r line; do if [[ "$line" == export* ]]; then eval "$line" fi done <<< "$detect_result" fi ``` The global wrapper contains the same pattern: ```bash detect_result=$("$SKILLS_DIR/init_dolphindb_env.py" --export 2>/dev/null) if [ $? -eq 0 ]; then while IFS= read -r line; do if [[ "$line" == export* ]]; then eval "$line" fi done <<< "$detect_result" fi ``` The legacy loader evaluates the complete output of another detector: ```bash # Run detection script and evaluate export statements eval "$(bash "$SCRIPT_DIR/detect_dolphindb_env.sh" 2>/dev/null)" ``` The Python detector emits values without shell-safe quoting: ```python if args.export: print(f"\n# Run the following commands in the shell:") print(f"export DOLPHINDB_PYTHON_BIN={python_path}") print(f"export DOLPHINDB_SDK_VERSION={version}") ``` ### Technical Analysis `eval` interprets its input as shell program text rather than as data. Merely checking that a line begins with `export` does not make the remainder safe. The evaluated values include Python interpreter paths, SDK version output, and environment paths. These values are derived from environment variables, local filesystem names, Conda command output, and Python module output. They are not consistently escaped for shell evaluation. Consequently, command substitutions, shell separators, quotes, re ...[truncated 1509 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/init_dolphindb_env.py:154
Finding

Automatic Installation of an Unpinned Third-Party Package Into Existing Python Environments

Content
View full analysis
/dev/null ``` The alternative finder performs the same operation: ```bash echo " Installing dolphindb into: \$$TARGET_VAR" $TARGET_PYTHON -m pip install dolphindb --quiet ``` ### Technical Analysis When the DolphinDB SDK is not found, the initialization process installs `dolphindb` automatically. The package has no pinned version and no hash verification. The package index is not restricted to a configured trusted repository, and installation may target the current interpreter, a system interpreter, or a Conda base environment. Python package installation executes package build and installation logic. Therefore, the effective code introduced into the local environment depends on package-index resolution at the time initialization runs. This creates supply-chain exposure and can unexpectedly mutate shared Python environments. The issue is aggravated by the documentation describing initialization as mandatory. ### Attack Path 1. A user invokes the mandatory environment initialization on a machine where the DolphinDB package is not installed. 2. `get_dolphindb_python()` uses its default `auto_install=Tr ...[truncated 1227 chars]
Remediation
View remediation
``` 4. Use a lock file or requirements file with cryptographic hashes and install with `--require-hashes`. 5. Restrict installation to an approved HTTPS package index. 6. Display the target interpreter, target environment, package version, and source before installation. 7. Refuse installation when running as root or an administrator unless an explicit override is provided. 8. Keep detection read-only; separate installation into a clearly named, opt-in setup command. 9. Verify the installed package version and provenance after installation. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:72
Finding

Documentation Encourages Predictable Administrative Database Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (44)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The basic skill explicitly includes delete and drop capabilities, yet the document does not warn about irreversible data loss or recommend safeguards. In this context, accidental invocation or misunderstood instructions could destroy databases, tables, or partitions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script is presented as a detector/export helper, but it also performs an undeclared state-changing action by installing the dolphindb package when none is found. In an agent skill context, hidden installation behavior is risky because callers may eval or invoke it expecting only discovery output, yet it modifies the host environment and pulls code from a package repository without explicit consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file presents itself as an environment detector, but the later logic changes system state by selecting a Python interpreter and installing the dolphindb package. In an agent skill, this mismatch is dangerous because a seemingly read-only discovery step can unexpectedly modify the host, introduce supply-chain risk, and violate least surprise for users and orchestrators.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is written entirely in Chinese, including operational instructions and user-facing notices, with no indication that users may choose another language. The policy explicitly flags language or locale constraints when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file presents all operational instructions, warnings, and usage guidance exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue unless the locale restriction is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide explicitly says that if no existing SDK environment is found, it will automatically install DolphinDB into a Python 3.13 environment, but it does not warn users that this modifies the local system or Python environment. In an agent skill context, undocumented package installation is risky because an automated assistant may perform persistent changes, introduce dependency conflicts, or alter a shared interpreter without informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The troubleshooting section instructs users to run pip install dolphindb after exporting a Python interpreter, but it does not disclose that this will change that interpreter's installed packages. In a skill used by an AI agent, such instructions can lead to silent, persistent environment modification and break unrelated workflows if the selected interpreter is global or shared.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language content throughout the file forces a single language/locale presentation, and there is no indication that users can choose another language or that the Chinese-only format is required for a region-specific purpose. This matches the policy category for language or locale constraints without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all user-facing instructions in Chinese, and there is no indication that users may choose another language or that the language restriction is intentionally limited to a specific audience. That can violate a language/locale policy requiring user choice or explicit justification for a forced language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly states that if no existing SDK is found, it will automatically install into a local Python 3.13 environment. Even though this is documentation rather than executable code, instructing an agent to modify the user's local environment without an explicit confirmation step can lead to unauthorized package installation, unexpected environment changes, and supply-chain exposure if package sources are not constrained. In this skill context, that behavior is more dangerous because the workflow is described as mandatory and automatic, which increases the chance an agent will perform system changes by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document begins entirely in Chinese and provides no indication that users may choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document advertises automatic installation support and environment detection without clearly warning that this may modify the user's system or install packages. In a skill context, users may follow these instructions and trigger unreviewed dependency installation, increasing supply-chain and integrity risks if package sources or install behavior are not tightly controlled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The release notes instruct users to source shell wrappers and emphasize persistent environment variables, but do not warn that sourcing executes shell code in the current session and can alter PATH, variables, and command behavior. In an agent-skill ecosystem, this is more dangerous because users may trust wrapper scripts without reviewing them, enabling privilege misuse, persistence, or session tampering if the scripts are later changed or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises database creation, modification, deletion, and automatic installation capabilities but does not clearly warn that these actions can alter data or the host environment. In an agent setting, omission of such warnings increases the risk of users authorizing destructive or system-changing operations without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example hardcodes admin / 123456, normalizing the use of default or weak credentials and potentially encouraging insecure deployments. If copied into real environments, this could lead to trivial unauthorized access to the database service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Docker deployment example starts a network-accessible container with exposed ports and persistent storage but provides no security guidance. Users may deploy an exposed service with default settings, creating attack surface for unauthorized access or misuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The Docker example pulls and runs dolphindb/dolphindb:latest, which is mutable and can change over time. This creates supply-chain and reproducibility risk: a future image update or registry compromise could cause users to deploy an unexpected or malicious image.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The Docker skill trigger list contains broad operational phrases like quick deployment and one-click install. This increases the chance that unrelated user requests could invoke deployment behavior, leading to unreviewed installation, container startup, or port exposure.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
#### 📖 详细文档

查看完整技能:`skills/dolphindb-docker/SKILL.md`

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger keywords for the quant-finance skill include broad terms such as strategy backtesting, query-like concepts, and common finance phrases without clear boundaries. In an agentic system, overly broad triggers can cause the skill to activate unexpectedly and perform sensitive DB or analytics actions outside the user's intended scope.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

md
#### 📖 详细文档

查看完整技能:`skills/dolphindb-basic/SKILL.md`

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
#### 📖 详细文档

查看完整技能:`skills/dolphindb-quant-finance/SKILL.md`

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The streaming skill trigger words include generic terms like real-time computation and monitoring with no exclusion criteria. In context, this can unintentionally route ordinary analytics requests into a skill capable of standing up streaming infrastructure or modifying database state.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 359)May include surrounding context.

md
#### 📖 详细文档

查看完整技能:`skills/dolphindb-streaming/SKILL.md`

---

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Lines L169-L172 describe a branch where missing SDK leads to 'automatic installation'. However, the concrete example implementation at L111-L121 only reports that the SDK is not installed and terminates with sys.exit(1). This is an intent/documentation contradiction rather than mere incompleteness because the document explicitly claims an automatic remediation path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.