Back to skill

Security audit

Hologres Privileges

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Hologres permission-management reference, but it includes copy-ready high-impact database administration commands with limited warnings or scoping.

Review this skill carefully before installing. Use it only with authorized Hologres administrative accounts, prefer role-based least-privilege grants, avoid copying PUBLIC, SUPERUSER, DROP, OWNER, or ALTER DATABASE examples into production without explicit review, and install hologres-cli from a trusted, pinned source where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Third-Party CLI Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–15
Vulnerability Type: Unpinned and unverified third-party dependency
Risk Level: Medium

Vulnerable Code

markdown
## Prerequisites

This skill requires **hologres-cli** to be installed first:

```bash
pip install hologres-cli
export HOLOGRES_SKILL=hologres-privileges
text

### Technical Analysis

The prerequisite installs `hologres-cli` without pinning a reviewed version, verifying cryptographic hashes, or specifying an explicitly trusted package index. As a result, the package and its transitive dependencies may change independently of the reviewed Skill.

Python package installation may execute package-controlled build or installation logic. The resulting CLI is then trusted to perform write-capable database operations through `hologres sql run --write`. A compromised package release, dependency, package repository, or resolution path could therefore introduce arbitrary local code execution.

This finding does not establish that `hologres-cli` is malicious. It identifies an unsafe and non-reproducible dependency installation process.

### Attack Path

1. An attacker compromises the `hologres-cli` distribution account, one of its transitive dependencies, or the package source used by `pip`.
2. The attacker publishes a malicious release or modifies a dependency selected by the unpinned installation.
3. A user follows the documented prerequisite and runs `pip install hologres-cli`.
4. `pip` downloads the attacker-controlled package and may execute malicious build or installation logic.
5. The installed CLI runs with the user's local privileges and may access environment variables, local files, database credentials, or authentication material available to that user.
6. Because the Skill relies on the CLI for write operations, a malicious implementation could alter SQL, execute unauthorized database commands, or exfiltrate accessible credentials and data.

### Impact Assessment

S
...[truncated 646 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin hologres-cli to a specifically reviewed release, for example:

    bash
    python -m pip install "hologres-cli==X.Y.Z"
    
  2. Record cryptographic hashes in a requirements or lock file and install with hash enforcement:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Pin and hash all transitive dependencies, not only the top-level package.

  4. Specify and document an explicitly trusted package index. Where feasible, use an internally controlled artifact repository containing reviewed package artifacts.

  5. Document the expected package publisher, package name, approved version, and integrity-verification procedure to reduce dependency-confusion and package-substitution risk.

  6. Install and run the CLI in an isolated virtual environment or container under a non-privileged operating-system account.

  7. Use a least-privileged Hologres account for routine operations. Require separate approval and credentials for ownership changes, role administration, or superuser operations.

  8. Review release changes and regenerate locked hashes before upgrading the dependency.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This section documents creation of superusers, promotion to SUPERUSER, password changes, ownership transfer, and user deletion without any explicit warning, approval gate, or least-privilege guidance attached to the dangerous examples. In an agent skill context, such examples can be operationalized directly and may lead users or downstream automation to perform privilege escalation or destructive account changes with production impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation includes GRANT ... TO PUBLIC, which grants access to every role, but does not clearly warn that this can massively broaden data exposure beyond the intended audience. In a permission-management skill, readers may copy this directly, resulting in unintended disclosure or modification access across the database.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The default-privileges examples grant future table access to PUBLIC, creating persistent automatic exposure for newly created objects, yet the text lacks an explicit warning about the long-lived blast radius. This is especially dangerous because it silently affects future tables and may be forgotten, causing ongoing unauthorized access as schemas evolve.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes generic phrases such as "permission denied", "default privileges", and "授权" that can match many ordinary database troubleshooting or authorization questions outside the narrow Hologres privilege-management scope. Overly broad routing can cause this skill to activate unexpectedly, increasing the chance that users receive privilege-changing guidance in contexts where they only wanted diagnosis or where a different skill should handle the request.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes the skill as focused on privilege management under the PostgreSQL authorization model: creating users, granting/revoking privileges, default privileges, diagnosis, and RBAC planning. This reference also documents ALTER ... OWNER TO, which changes object ownership and grants full control including DROP and ALTER, expanding beyond ordinary privilege administration into object ownership/DDL control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document presents ownership transfer, role grants, role removal, and role deletion as copy-ready commands without an explicit warning about irreversible or high-impact consequences. In a permission-management skill, operators may treat the reference as safe-by-default guidance and unintentionally transfer control, break access paths, or disrupt production authorization models.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest frames the skill around user/role privileges, schema/table/column/view authorization, default privileges, and permission troubleshooting. The catalog RLS section instructs changing a database setting via ALTER DATABASE ... SET, which is a broader database configuration capability rather than standard privilege grant/revoke management.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file describes enabling or disabling catalog row-level security with superuser database-level commands but does not warn about metadata visibility changes, troubleshooting impact, or application/monitoring compatibility risks. Because this skill is specifically about permissions, readers may apply the setting in production and unintentionally impair discovery, diagnostics, or administrative workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.