{"data":{"skill":{"slug":"tencentcloudbase-relational-database-mcp-cloudbase","name":"relational-database-mcp-cloudbase","icon":"📦","repo":"https://github.com/tencentcloudbase/skills/tree/main/skills/relational-database-tool","status":"approved","author":"tencentcloudbase","authorVersion":"2.23.8","skillstoreRevision":1},"audit":{"id":"80bdc2e1-99ed-4e53-aed1-4132205fe82e","skill_id":"b3de8da2-ba26-4db1-b749-9cd6e738845e","version":2,"content_hash":"v3:24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec:492769568feac99b674424a5ad7fd738fb526e91aeaf05bddcae89c529d7a36c:45ae12ea08ba7b8d608cb5c767cce190f3075c98b508d3eefce125eb420ed4ee:736b696c6c732f74656e63656e74636c6f7564626173652f72656c6174696f6e616c2d64617461626173652d6d63702d636c6f756462617365:3a27df240cc21ba358216c1ecee1181a","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most static command, filesystem, and blocker findings are false positives caused by Markdown formatting and static documentation references. The hardcoded remote fallback URLs are a confirmed low-risk network concern, and the remote instruction fallback is a medium supply-chain trust concern.","remediation":[{"issue":"Remote fallback URLs can load instructions outside the audited package.","severity":"medium","suggestion":"Bundle related guidance in the package, or pin fallback URLs to immutable commits and require user confirmation before loading them."},{"issue":"The skill guides destructive database operations such as destroying MySQL or running DDL.","severity":"medium","suggestion":"Require exact environment, table, and action confirmation before destroy, delete, drop, or schema migration steps."},{"issue":"Permission updates can expose SQL data when applied too broadly.","severity":"low","suggestion":"Use least-privilege permission examples and require queryPermissions verification after every permission update."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":90,"line_start":90},{"file":"SKILL.md","line_end":99,"line_start":94},{"file":"SKILL.md","line_end":101,"line_start":99},{"file":"SKILL.md","line_end":105,"line_start":101},{"file":"SKILL.md","line_end":106,"line_start":105},{"file":"SKILL.md","line_end":107,"line_start":106},{"file":"SKILL.md","line_end":107,"line_start":107},{"file":"SKILL.md","line_end":110,"line_start":108},{"file":"SKILL.md","line_end":112,"line_start":110},{"file":"SKILL.md","line_end":114,"line_start":112},{"file":"SKILL.md","line_end":116,"line_start":114},{"file":"SKILL.md","line_end":128,"line_start":116},{"file":"SKILL.md","line_end":130,"line_start":128},{"file":"SKILL.md","line_end":136,"line_start":130},{"file":"SKILL.md","line_end":138,"line_start":136},{"file":"SKILL.md","line_end":145,"line_start":138},{"file":"SKILL.md","line_end":149,"line_start":145},{"file":"SKILL.md","line_end":150,"line_start":149},{"file":"SKILL.md","line_end":150,"line_start":150},{"file":"SKILL.md","line_end":151,"line_start":151},{"file":"SKILL.md","line_end":160,"line_start":159},{"file":"SKILL.md","line_end":162,"line_start":160},{"file":"SKILL.md","line_end":163,"line_start":162},{"file":"SKILL.md","line_end":164,"line_start":163},{"file":"SKILL.md","line_end":165,"line_start":164},{"file":"SKILL.md","line_end":165,"line_start":165},{"file":"SKILL.md","line_end":169,"line_start":169},{"file":"SKILL.md","line_end":177,"line_start":170},{"file":"SKILL.md","line_end":178,"line_start":177},{"file":"SKILL.md","line_end":178,"line_start":178},{"file":"SKILL.md","line_end":183,"line_start":182},{"file":"SKILL.md","line_end":188,"line_start":183}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Remote Instruction Fallback Expands Trust Boundary","locations":[{"file":"SKILL.md","line_end":15,"line_start":12},{"file":"SKILL.md","line_end":30,"line_start":27}],"confidence":0.84,"description":"The skill tells agents to use published raw URLs as fallback sources for main and sibling skill instructions. Those instructions are outside the packaged audited artifact and could change after review.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The remote fallback URLs and sibling skill instructions are explicit in SKILL.md. I found no malicious text, but the trust-boundary expansion is real."}],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":12,"line_start":12}],"confidence":0.78,"description":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This is a hardcoded remote documentation URL used as a fallback source. It does not exfiltrate data, but it can make agents consume instructions outside the audited package."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":13,"line_start":13}],"confidence":0.78,"description":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This is a hardcoded remote documentation URL used as a fallback source. It does not exfiltrate data, but it can make agents consume instructions outside the audited package."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":29,"line_start":29}],"confidence":0.78,"description":"- Web application integration -> `../relational-database-web/SKILL.md` (standalone fallback: `https:","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This is a hardcoded remote documentation URL used as a fallback source. It does not exfiltrate data, but it can make agents consume instructions outside the audited package."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":30,"line_start":30}],"confidence":0.78,"description":"- Raw HTTP database access -> `../http-api/SKILL.md` (standalone fallback: `https://cnb.cool/tencent","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This is a hardcoded remote documentation URL used as a fallback source. It does not exfiltrate data, but it can make agents consume instructions outside the audited package."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":211,"audit_model":"codex","audited_at":"2026-07-09T16:44:03.807+00:00","created_at":"2026-07-15T09:20:56.248834+00:00","static_findings":[{"id":"external_commands:SKILL.md:3:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"description: This is the required documentation for agents operating on the CloudBase Relational Dat","category":"external_commands","line_end":3,"severity":"medium","line_start":3},{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If this environment only installed the current skill, start from the CloudBase main entry and use th","category":"external_commands","line_end":10,"severity":"medium","line_start":10},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Keep local `references/...` paths for files that ship with the current skill directory. When this fi","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The task includes `queryMysqlDatabase`, `manageMysqlDatabase`, `queryPermissions`, or `managePermi","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Web application integration -> `../relational-database-web/SKILL.md` (standalone fallback: `https:","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Raw HTTP database access -> `../http-api/SKILL.md` (standalone fallback: `https://cnb.cool/tencent","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Skipping `_openid` and permissions review after creating new SQL tables.","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If you can call tools like `queryMysqlDatabase`, `manageMysqlDatabase`, `queryPermissions`, `manag","category":"external_commands","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Read-only SQL and provisioning status checks -> `queryMysqlDatabase`","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- MySQL provisioning, MySQL destruction, write SQL, DDL, schema initialization -> `manageMysqlDataba","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Inspect permissions -> `queryPermissions(action=\"getResourcePermission\")`","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Change permissions -> `managePermissions(action=\"updateResourcePermission\")`","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Prefer `queryMysqlDatabase(action=\"getInstanceInfo\")` or a read-only SQL check before writes.","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### 1. `queryMysqlDatabase`","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Running `SELECT` and other read-only SQL queries with `action=\"runQuery\"`","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Checking whether MySQL already exists with `action=\"getInstanceInfo\"`","category":"external_commands","line_end":89,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Inspecting asynchronous provisioning progress with `action=\"describeCreateResult\"` or `action=\"des","category":"external_commands","line_end":90,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":99,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":101,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### 2. `manageMysqlDatabase`","category":"external_commands","line_end":105,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Provisioning MySQL with `action=\"provisionMySQL\"`","category":"external_commands","line_end":106,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Destroying MySQL with `action=\"destroyMySQL\"`","category":"external_commands","line_end":107,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Executing `INSERT`, `UPDATE`, `DELETE`, `CREATE TABLE`, `ALTER TABLE`, `DROP TABLE` with `action=\"","category":"external_commands","line_end":107,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Initializing tables and indexes with `action=\"initializeSchema\"`","category":"external_commands","line_end":110,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Important:** When creating a new table, you **must** include the `_openid` column for per-user acc","category":"external_commands","line_end":112,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```sql","category":"external_commands","line_end":114,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":116,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Note: when a user is logged in, `_openid` is automatically populated by the server from the authenti","category":"external_commands","line_end":128,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- You are prepared to query `describeTaskStatus` afterward to inspect the destroy result.","category":"external_commands","line_end":130,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### 3. `queryPermissions`","category":"external_commands","line_end":136,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Call shape: `queryPermissions(action=\"getResourcePermission\", resourceType=\"sqlDatabase\", resource","category":"external_commands","line_end":138,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### 4. `managePermissions`","category":"external_commands","line_end":145,"severity":"medium","line_start":138},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Call shape: `managePermissions(action=\"updateResourcePermission\", resourceType=\"sqlDatabase\", reso","category":"external_commands","line_end":149,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Canonical plugin name: `permissions`","category":"external_commands","line_end":150,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Legacy plugin aliases `security-rule`, `security-rules`, `secret-rule`, `secret-rules`, and `acces","category":"external_commands","line_end":150,"severity":"medium","line_start":150},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Legacy tools `readSecurityRule` and `writeSecurityRule` are removed; always use `queryPermissions`","category":"external_commands","line_end":151,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Call `queryMysqlDatabase(action=\"getInstanceInfo\")`.","category":"external_commands","line_end":160,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. If no instance exists, call `manageMysqlDatabase(action=\"provisionMySQL\", confirm=true)`.","category":"external_commands","line_end":162,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `queryMysqlDatabase(action=\"describeCreateResult\")`","category":"external_commands","line_end":163,"severity":"medium","line_start":162},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `queryMysqlDatabase(action=\"describeTaskStatus\")`","category":"external_commands","line_end":164,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Only continue when the returned lifecycle status is `READY`.","category":"external_commands","line_end":165,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. For MySQL provisioning, prefer `describeCreateResult`; reserve `describeTaskStatus` for destroy f","category":"external_commands","line_end":165,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Use `queryMysqlDatabase(action=\"runQuery\")` with a limited `SELECT`.","category":"external_commands","line_end":169,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Include `LIMIT` and relevant filters.","category":"external_commands","line_end":177,"severity":"medium","line_start":170},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Run them through `manageMysqlDatabase(action=\"initializeSchema\")`.","category":"external_commands","line_end":178,"severity":"medium","line_start":177},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. After creating tables, verify permissions with `queryPermissions` or `managePermissions`.","category":"external_commands","line_end":178,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Use `queryMysqlDatabase(action=\"runQuery\")` to inspect current data or schema if needed.","category":"external_commands","line_end":183,"severity":"medium","line_start":182},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Run the mutation once with `manageMysqlDatabase(action=\"runStatement\")`.","category":"external_commands","line_end":188,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Use `queryMysqlDatabase(action=\"getInstanceInfo\")` to confirm the current environment still has a","category":"external_commands","line_end":189,"severity":"medium","line_start":188},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Call `manageMysqlDatabase(action=\"destroyMySQL\", confirm=true)`.","category":"external_commands","line_end":190,"severity":"medium","line_start":189},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Query `queryMysqlDatabase(action=\"describeTaskStatus\")` until the destroy task completes or fails","category":"external_commands","line_end":191,"severity":"medium","line_start":190},{"id":"network:SKILL.md:12:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:SKILL.md:29:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Web application integration -> `../relational-database-web/SKILL.md` (standalone fallback: `https:","category":"network","line_end":29,"severity":"low","line_start":29},{"id":"network:SKILL.md:30:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Raw HTTP database access -> `../http-api/SKILL.md` (standalone fallback: `https://cnb.cool/tencent","category":"network","line_end":30,"severity":"low","line_start":30},{"id":"filesystem:SKILL.md:29:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Web application integration -> `../relational-database-web/SKILL.md` (standalone fallback: `https:","category":"filesystem","line_end":29,"severity":"high","line_start":29},{"id":"filesystem:SKILL.md:30:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Raw HTTP database access -> `../http-api/SKILL.md` (standalone fallback: `https://cnb.cool/tencent","category":"filesystem","line_end":30,"severity":"high","line_start":30},{"id":"blocker:SKILL.md:113:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"_openid VARCHAR(64) DEFAULT '' NOT NULL","category":"blocker","line_end":113,"severity":"low","line_start":113},{"id":"blocker:SKILL.md:210:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"When working as an MCP agent, **always prefer these MCP tools** for CloudBase Relational Database, a","category":"blocker","line_end":210,"severity":"low","line_start":210},{"id":"blocker:SKILL.md:30:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- Raw HTTP database access -> `../http-api/SKILL.md` (standalone fallback: `https://cnb.cool/tencent","category":"blocker","line_end":30,"severity":"low","line_start":30}],"finding_verdicts":[{"id":"external_commands:SKILL.md:3:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"This line is Markdown documentation using backticks or code fences to format tool names, SQL, or examples. SKILL.md has no runnable shell or Ruby code at this location.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:12:hardcoded-url","reason":"This is a hardcoded remote documentation URL used as a fallback source. It does not exfiltrate data, but it can make agents consume instructions outside the audited package.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"network:SKILL.md:13:hardcoded-url","reason":"This is a hardcoded remote documentation URL used as a fallback source. It does not exfiltrate data, but it can make agents consume instructions outside the audited package.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"network:SKILL.md:29:hardcoded-url","reason":"This is a hardcoded remote documentation URL used as a fallback source. It does not exfiltrate data, but it can make agents consume instructions outside the audited package.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"network:SKILL.md:30:hardcoded-url","reason":"This is a hardcoded remote documentation URL used as a fallback source. It does not exfiltrate data, but it can make agents consume instructions outside the audited package.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"filesystem:SKILL.md:29:path-traversal-sequence","reason":"The ../ string is a static Markdown reference to a sibling skill, not a user-controlled filesystem operation. No executable arbitrary file read is present in this file.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:30:path-traversal-sequence","reason":"The ../ string is a static Markdown reference to a sibling skill, not a user-controlled filesystem operation. No executable arbitrary file read is present in this file.","verdict":"false_positive","confidence":0.84},{"id":"blocker:SKILL.md:113:system-reconnaissance","reason":"The flagged text is a SQL column name used for CloudBase per-user access control. It is not host system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:210:system-reconnaissance","reason":"The line instructs agents to prefer CloudBase MCP tools for database work. It does not enumerate local system details or collect host information.","verdict":"false_positive","confidence":0.9},{"id":"blocker:SKILL.md:30:network-reconnaissance","reason":"The line links to related HTTP API documentation. It does not describe probing networks, scanning hosts, or discovering services.","verdict":"false_positive","confidence":0.88}],"semantic_findings":[{"title":"Remote Instruction Fallback Expands Trust Boundary","severity":"medium","locations":[{"file":"SKILL.md","line_end":15,"line_start":12},{"file":"SKILL.md","line_end":30,"line_start":27}],"confidence":0.84,"description":"The skill tells agents to use published raw URLs as fallback sources for main and sibling skill instructions. Those instructions are outside the packaged audited artifact and could change after review.","confidence_reasoning":"The remote fallback URLs and sibling skill instructions are explicit in SKILL.md. I found no malicious text, but the trust-boundary expansion is real."}],"subject_marketplace_commit_sha":"24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec","subject_content_hash":"492769568feac99b674424a5ad7fd738fb526e91aeaf05bddcae89c529d7a36c","subject_tree_hash":"45ae12ea08ba7b8d608cb5c767cce190f3075c98b508d3eefce125eb420ed4ee","subject_plugin_path":"skills/tencentcloudbase/relational-database-mcp-cloudbase","audit_payload_hash":"3a27df240cc21ba358216c1ecee1181a","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec","contentHash":"492769568feac99b674424a5ad7fd738fb526e91aeaf05bddcae89c529d7a36c","treeHash":"45ae12ea08ba7b8d608cb5c767cce190f3075c98b508d3eefce125eb420ed4ee","pluginPath":"skills/tencentcloudbase/relational-database-mcp-cloudbase","auditPayloadHash":"3a27df240cc21ba358216c1ecee1181a"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":4,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}