Back to skill

Security audit

Mindsdb Mcp Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent MindsDB purpose, but it gives an agent broad database and model-operation authority without enough scoping or confirmation safeguards.

Install only if you intend to let an agent use MindsDB against approved data sources. Use read-only or least-privilege credentials by default, avoid production systems until you add confirmation and audit controls, do not put real API keys in URLs or prompts, pin dependency versions, and require explicit approval for CREATE/INSERT/UPDATE/DELETE/DROP, imports/exports, SaaS connections, RAG ingestion, scheduled jobs, and production model deployment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
INSTALL.md:74
Finding

API Credentials Embedded in URL Query Strings

Content
View full analysis
Remediation
View remediation
``` 4. Use short-lived, narrowly scoped tokens restricted to the exact tools and data sources needed. 5. Configure clients, proxies, observability platforms, and exception handlers to redact authorization material and sensitive query parameters. 6. Ensure configuration files containing token references have restrictive file permissions and are excluded from version control and support bundles. 7. Rotate any real keys that have previously been placed in URLs. 8. Document a revocation and incident-response process for leaked credentials. ]]>

T08 · Insecure Dependencies

Warning
Location
INSTALL.md:16
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
" npm install "mindsdb-js@" npm install --global "@mindsdb/mcp-server@" ``` 2. Maintain lockfiles for runnable examples and integrations, such as `package-lock.json` or a Python lockfile generated by an approved dependency-management tool. 3. Use hash verification for Python packages where supported: ```text mindsdb== --hash=sha256: ``` 4. Prefer isolated virtual environments and project-local npm installations over global installation. 5. Avoid recommending automatic global updates. Review release notes, provenance, signatures, and dependency changes before upgrading. 6. Restrict installations to approved registries and enable registry integrity and provenance controls where available. 7. Run dependency vulnerability and malware scanning in CI before publishing updated version recommendations. 8. Do not run package installation as root or administrator unless strictly necessary. 9. Document known-good package versions and a controlled upgrade procedure so installation remains reproducible. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (40)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description defines activation so broadly that it can trigger for almost any database, analytics, RAG, or multi-source data task, even when MindsDB is unnecessary. This creates an overreach risk where the agent may route users into a powerful database-manipulation skill by default, increasing the chance of unintended data access, schema changes, model creation, or external service connections without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/data-sources.md (reported line 321)May include surrounding context.

PARAMETERS = { 'project': 'my-project', 'dataset': 'mydataset', 'credentials': '/path/to/credentials.json' }

text

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/data-sources.md (reported line 378)May include surrounding context.

PARAMETERS = { 'project': 'my-project', 'dataset': 'mydataset', 'credentials': '/path/to/credentials.json' }

text

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file is written as a normative compliance checklist and begins with a Chinese-only title, while later marking bilingual support as a requirement/compliance criterion. For the current file itself, there is no indication that Chinese is optional or that the locale constraint is justified, which can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L012明确声明“MindsDB已内置MCP服务器功能,无需单独安装MCP服务器”,并给出直接安装并启动 mindsdb 的步骤。但后文又在L112-L117、L169-L183要求通过 npm 安装、卸载和更新独立的 @mindsdb/mcp-server,这与前述安装意图直接冲突,可能导致用户部署错误组件。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installation examples instruct users to place authentication tokens and API keys into configuration values without warning about protecting those secrets. In a skill designed to access many enterprise data sources, this increases the chance that users will hardcode live credentials into files, share them inadvertently, or commit them to source control.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 41)May include surrounding context.

传统方式 / Traditional Approach:

sql
-- 需要手动编写SQL / Need to write SQL manually
CREATE DATABASE my_postgres 
WITH ENGINE = 'postgres',
PARAMETERS = {"host": "127.0.0.1", "port": 5432, ...};

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly describes the agent automatically connecting to databases, creating models, and running predictions, but it does not warn that these actions can create persistent resources, access sensitive enterprise data, or trigger external side effects. In an agent skill context, natural-language instructions can cause users to authorize actions they may not realize are state-changing, which increases the risk of unintended database modifications or data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installation/configuration guidance instructs users to configure live MCP endpoints and authorization tokens, but does not include privacy or security guidance around credential storage, localhost exposure, token handling, or least-privilege access. This can lead users to paste privileged credentials into agent-connected environments without understanding the risk of data exfiltration or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow and operation descriptions present database connections, query execution, data-source management, and model/RAG creation as routine actions without prominent user-facing warnings about destructive, privacy-impacting, or cost-incurring consequences. In a skill designed to interact with 200+ enterprise data sources, omission of explicit safeguards makes accidental unsafe execution more likely, especially for non-technical users relying on natural-language automation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All natural-language guidance in the file is presented in Chinese, which effectively forces a specific language on users without any visible opt-in or justification. The policy explicitly calls for flagging language or locale constraints unless the skill offers user choice or clearly documents a justified regional requirement.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 154)May include surrounding context.

  1. 验证连接参数
    sql
    CREATE DATABASE test_connection
    WITH ENGINE = 'mysql',
    PARAMETERS = {
      'host': 'correct-host',
    

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide includes concrete database connection examples with hosts, usernames, and plaintext passwords, but provides no warning about secret handling, least-privilege accounts, or the risk of connecting to production systems. In an agent skill that encourages natural-language database operations across many enterprise data sources, this can normalize unsafe credential practices and lead users to expose real secrets or grant overly broad access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document demonstrates import/export operations on local files without warning that these actions can read sensitive local data or overwrite/exfiltrate files. Because this skill is intended for broad database and document workflows, users may invoke file operations implicitly through the agent, increasing the chance of unintended data exposure or destructive writes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The evaluation prompts are extremely broad and instruct the skill to handle many high-impact actions such as querying databases, connecting external services, importing documents, deploying models, and configuring monitoring, but they do not define trigger boundaries, safety preconditions, or exclusion rules. In a skill that can access enterprise data sources and execute database-related operations, this increases the risk of over-triggering, unintended privileged actions, and unsafe handling of sensitive data requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

All natural-language examples in the file are presented in Chinese, and there is no indication that users may choose another language or that the skill is intentionally region-specific. This can violate language/locale policy when a skill appears to enforce one language by default without consent or documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation includes example fields for secrets such as OAuth credential files, API tokens, passwords, and security tokens in a skill specifically designed to connect to many enterprise data sources. Even though the values are placeholders, presenting them inline without an adjacent warning about secure secret handling can normalize pasting real credentials into prompts, configs, logs, or version-controlled files, increasing the risk of credential exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide provides examples for ingesting legal, medical, and call-recording data into knowledge bases without any caution about PII, consent, retention, jurisdictional compliance, or model-access controls. In this skill's context—encouraging natural-language interaction with many enterprise data sources—such examples can normalize unsafe handling of regulated data and lead users to expose sensitive records to retrieval systems or third-party models.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly supports connecting to external databases using usernames and passwords, but provides no guidance on secure credential handling, secret storage, least-privilege access, or privacy implications. In an agent skill that can bridge to 200+ enterprise data sources, this omission can lead users or downstream agents to pass raw credentials insecurely, increasing the risk of credential leakage and unauthorized data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The export feature allows query results to be written to a destination path, but the documentation does not warn that this can exfiltrate sensitive data, create unsecured local files, or write to unintended locations. In the context of a data-integration skill, export operations are especially sensitive because they can move large volumes of enterprise data outside the original access boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file includes examples that deploy models to production endpoints and stages, including direct deployment commands in lifecycle management and GitHub Actions automation. The surrounding documentation does not warn that these actions can change live inference behavior or affect production systems, which is a user/system integrity concern under the markdown-file warning rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains natural-language guidance exclusively in Chinese, and there is no indication that users may choose another language or that the content is intentionally restricted to a Chinese-speaking audience. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sdk-api.md (reported line 205)May include surrounding context.

bash
# 使用API密钥
curl -H "Authorization: Bearer YOUR_API_KEY" \
  http://localhost:47334/api/models

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is presented as SQL query examples, but it also includes data-modifying and schema-destructive statements such as INSERT, UPDATE, DELETE, ALTER TABLE, and DROP TABLE. In the context of an MCP skill that encourages natural-language database operations across many enterprise data sources, these examples can normalize unsafe operations and increase the chance that an agent or user issues destructive commands against live systems without sufficient safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Destructive SQL examples are shown with no cautionary language, despite including operations that can delete rows, alter schemas, or drop tables. Because this skill is designed to be used by an agent for broad database interaction, omission of warnings materially raises the risk of accidental destructive execution by users or downstream automation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/sdk-api.md:537