relational-database-mcp-cloudbase

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The queryMysqlDatabase tool includes an action="getConnectionInfo" which is explicitly documented to return raw connection and cluster payloads that may include database credentials, such as host information and passwords.
  • [COMMAND_EXECUTION]: The skill provides the manageMysqlDatabase tool with the action="runStatement" capability, allowing for the execution of arbitrary SQL commands. This includes highly destructive operations such as DROP TABLE, DELETE, and ALTER TABLE, which can significantly impact database integrity and availability.
  • [DYNAMIC_EXECUTION]: Both queryMysqlDatabase and manageMysqlDatabase rely on the execution of dynamic SQL strings passed as arguments to the tools. This pattern allows the agent to construct and execute logic at runtime, increasing the risk of unintended database operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection via database content processing.
  • Ingestion points: The agent ingests untrusted data from external database records using queryMysqlDatabase(action="runQuery").
  • Boundary markers: There are no formal delimiters or boundary markers specified for the database content returned to the agent.
  • Capability inventory: The skill possesses powerful capabilities including database modification/destruction (manageMysqlDatabase) and permission management (managePermissions).
  • Sanitization: There is no mention of sanitization, filtering, or validation for the data returned from the database before it is processed by the agent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — relational-database-mcp-cloudbase