relational-database-mcp-cloudbase
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The
queryMysqlDatabasetool includes anaction="getConnectionInfo"which is explicitly documented to return raw connection and cluster payloads that may include database credentials, such as host information and passwords. - [COMMAND_EXECUTION]: The skill provides the
manageMysqlDatabasetool with theaction="runStatement"capability, allowing for the execution of arbitrary SQL commands. This includes highly destructive operations such asDROP TABLE,DELETE, andALTER TABLE, which can significantly impact database integrity and availability. - [DYNAMIC_EXECUTION]: Both
queryMysqlDatabaseandmanageMysqlDatabaserely on the execution of dynamic SQL strings passed as arguments to the tools. This pattern allows the agent to construct and execute logic at runtime, increasing the risk of unintended database operations. - [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection via database content processing.
- Ingestion points: The agent ingests untrusted data from external database records using
queryMysqlDatabase(action="runQuery"). - Boundary markers: There are no formal delimiters or boundary markers specified for the database content returned to the agent.
- Capability inventory: The skill possesses powerful capabilities including database modification/destruction (
manageMysqlDatabase) and permission management (managePermissions). - Sanitization: There is no mention of sanitization, filtering, or validation for the data returned from the database before it is processed by the agent.
Recommendations
- AI detected serious security threats
Audit Metadata