Back to plugin

Security audit

MySQL AIops

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate MySQL/MariaDB administration plugin, but it can make real database changes when connected with a privileged account.

Use this only for MySQL/MariaDB administration. Start with a read-only database account unless you intentionally want the agent to perform write operations, and provide write privileges or MYSQL_AIOPS_MASTER_PASSWORD only in environments where killing sessions, changing globals, and altering indexes are acceptable.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
skills/mysql-aiops/references/agent-guardrails.md:38
Evidence
Copy this into your agent's system prompt: