Back to skill

Security audit

sql-to-er

Security checks for vulnerabilities and agentic risk

Overview

This ER-diagram skill is mostly coherent, but it sends raw SQL/schema content to a third-party API by default, which users should review before installing.

Install only if you are comfortable with SQL DDL being sent to yanleaf.com by default. For private or production schemas, use the documented local mode with --no-api and avoid running the optional global pip mirror or sudo install commands unless you specifically need them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 6)May include surrounding context.

text
*.egg-info/
.venv/
venv/
.env
!docs/
!assets/
/*.png

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose centers on producing ER diagrams from schema inputs, with Word output mentioned only as an optional format on request. However, this code chunk's actual function is exclusively to create a formatted Word document summarizing tables and columns. That is a materially different primary behavior from diagram generation. While Word export could be a supporting feature within a larger ER tool, this specific code does not implement ER-diagram generation or SQL parsing at all, and instead implements a standalone export path for documentation. Therefore the description does not accurately represent this code chunk's behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description and code align at a high level only in that both concern ER diagram generation. However, the implementation materially differs from the declared behavior. The script accepts already-structured JSON/YAML models, not SQL DDL text or natural-language requests, and there is no SQL parser or external API integration. The outputs also differ: the script can generate Mermaid, DOT, PNG, SVG, and GoJS JSON, with default format set to 'all', whereas the description says outputs are limited to what the user asked for and Chen PNG is the default. The code additionally supports crow's-foot style, which is a meaningful undeclared capability. These are substantive behavior mismatches, not minor implementation details.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The primary description is written as producing a '经典 Chen 风格 ER 图 & Word 三线表设计文档', indicating a Chinese-language documentation/output expectation. The README does not offer language selection or explain that the skill is intentionally limited to a Chinese locale, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that parsing prefers the yanleaf remote API with local fallback, but it does not clearly disclose that users' SQL/DDL may be transmitted off-machine by default. In a skill that may process proprietary schemas, this creates a real confidentiality risk because internal table names, relationships, and business structure can be exposed to a third party without informed consent.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 36)May include surrounding context.

md
|------|------|
| Windows | [Graphviz 安装包](https://graphviz.org/download/) 或 `winget install Graphviz.Graphviz`(Chocolatey 需管理员时可用安装包/便携版) |
| macOS | `brew install graphviz` |
| Ubuntu/Debian | `sudo apt install graphviz` |
| Fedora | `sudo dnf install graphviz` |

装不上可忽略,PNG 仍可用。

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

md
|------|------|
| Windows | [Graphviz 安装包](https://graphviz.org/download/) 或 `winget install Graphviz.Graphviz`(Chocolatey 需管理员时可用安装包/便携版) |
| macOS | `brew install graphviz` |
| Ubuntu/Debian | `sudo apt install graphviz` |
| Fedora | `sudo dnf install graphviz` |

装不上可忽略,PNG 仍可用。

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 49)May include surrounding context.

md
|------|------|
| Windows | [Graphviz 安装包](https://graphviz.org/download/) 或 `winget install Graphviz.Graphviz`(Chocolatey 需管理员时可用安装包/便携版) |
| macOS | `brew install graphviz` |
| Ubuntu/Debian | `sudo apt install graphviz` |
| Fedora | `sudo dnf install graphviz` |

装不上可忽略,PNG 仍可用。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises file read/write and network-reachable behavior through its documented workflows, but it does not declare any tool scope or permission boundaries. In an agent environment, missing explicit permissions increases the chance the skill can access local files or transmit data more broadly than users expect, especially when handling SQL schemas that may contain sensitive structure or identifiers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that SQL parsing is sent first to a remote yanleaf.com API, but it does not warn users that their schema or DDL may leave the local environment. Database schemas often reveal internal system design, tenant names, business objects, and security-relevant structure, so silent transmission to a third party creates a meaningful confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function sends arbitrary user-provided SQL schema content to a third-party service by default, which can disclose proprietary database structure, table names, and embedded comments or sample literals without explicit consent at the point of use. In the context of an ER-diagram skill, users may paste internal production DDL, making this data exfiltration risk more serious than a generic outbound request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several exception messages are hard-coded in Chinese, which imposes a specific language on users regardless of their locale or preference. The policy allows locale constraints only when users are offered a choice or when the constraint is clearly documented and justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring explicitly states that it exports to a Chinese academic-style Word document, which enforces a specific locale and language convention by default. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is clearly documented as a justified region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The function signature defaults the document title to Chinese, and the implementation later uses Chinese-only labels for headers and footer text. This makes the generated output Chinese by design, with no user-selectable locale or language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The relationship label is forced to the Chinese string "(关联)", which imposes a specific language in generated output regardless of user preference. The file does not offer a locale option or document that this renderer is intentionally region-specific, so this appears to violate the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script sends raw SQL input to a remote API by default, which can expose proprietary schema details, table names, and embedded comments or literals to a third party without explicit user consent. In an ERD-generation skill, users may paste internal database DDL, so silent network transmission materially increases confidentiality risk in normal use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill should output only the requested artifact, with Chen PNG as the default and Mermaid/Word/GoJS only on request. Here, the default format is set to "all", and later expands to Mermaid, DOT, PNG, SVG, GoJS, and Word outputs, so the implementation performs substantially broader output generation than the stated behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

When args.format is "all", the code expands the request into six different artifact types and then writes them to disk. This contradicts the manifest's claim that the skill outputs only what the user asked for, and that non-PNG formats are produced only on request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language comments in Chinese, and later docstrings also continue in Chinese, which imposes a specific language context on maintainers or users of the skill without any opt-in or documented locale justification. The stated policy requires flagging language or locale constraints when they are forced rather than optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language documentation in this section is written only in Chinese and does not offer a language choice or explain a justified regional requirement. That makes the skill's operational guidance language-specific in a way that may violate organizational language policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This docstring communicates important parser behavior exclusively in Chinese, which can restrict comprehension based on language rather than technical role. Under the policy, language-specific instructions should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.