# Defense-in-Depth Score: DB-GPT

**Repo:** https://github.com/eosphoros-ai/DB-GPT · **Commit:** `5905245a6750bafa636aa36a904b7fd4ead75334` · **Reviewed:** 2026-10-03
**What it is:** Agentic AI data assistant: text-to-SQL, multi-agent workflows, code execution over databases
**Category:** Data & Analytics
**Scored configuration:** Webserver started with `dbgpt start` using the setup-wizard config (setup-wizard defaults, SANDBOX_RUNTIME unset so local execution), ReAct data agent at /api/v1/chat/react-agent in full tool mode.
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory yes · untrusted input yes · third party extensions yes · sub agents yes · external communication yes

## Score: 1.9 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L0 | L0 | L0 | L0 | 0.00 | — | **0.00** | High |
| C2 | Approval gates | L2 | L0 | L1 | L0 | 0.20 | C2-SELFAPPROVE | **0.20** | High |
| C3 | Tool & action scoping | L1 | L1 | L0 | L0 | 0.15 | — | **0.15** | High |
| C4 | Code-execution isolation | L2 | L1 | L2 | L2 | 0.42 | G1 | **0.42** (alt) | High |
| C5 | Untrusted input blast radius | L0 | L0 | L0 | L0 | 0.00 | C5-PUBLICTRIGGER | **0.00** | High |
| C6 | Memory, context & configuration integrity | L0 | L0 | L1 | L0 | 0.05 | — | **0.05** | Medium |
| C7 | Third-party extensions | L0 | L0 | L0 | L0 | 0.00 | C7-RCELOAD | **0.00** | High |
| C8 | Secrets & sensitive-data protection | L1 | L1 | L1 | L0 | 0.20 | — | **0.20** | High |
| C9 | Audit & traceability | L2 | L2 | L1 | L1 | 0.40 | — | **0.40** | High |
| C10 | Limits & kill switch | L2 | L2 | L2 | L1 | 0.45 | — | **0.45** | High |


As shipped, DB-GPT's data agent runs model-written shell commands and Python directly on the server host with the server's full environment, including its API keys, and none of it needs human approval. The web server's default network exposure and authentication are not locked down. The Docker sandbox is opt-in, and even then skill scripts run on the host. Treat a default install as remote code execution for anyone who controls data the agent reads.

## Critical gaps
- The shell and Python tools skip approval entirely, and the connector approval gate is not a strict boundary. (ASI09, ASI02, T10; C2)
- Model-generated Python and shell run as host subprocesses by default with the server's full environment, including API keys. (ASI05, T11, LLM05; C4) — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py:25](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py#L25); [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py:222](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py#L222); [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/config.py:40-42](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/config.py#L40-L42)
- A hijacked agent can both leak data (curl from the host shell) and take irreversible actions (SQL writes, shell) with no human involved. (ASI01, LLM01, T6; C5) — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py:23](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py#L23); [packages/dbgpt-core/src/dbgpt/datasource/rdbms/base.py:628-631](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/datasource/rdbms/base.py#L628-L631)
- The model can install and run third-party packages on the host by default (the shell tool advertises pip/apt), and imported skill scripts run with the full server environment. (ASI04, T17, LLM03; C7) — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py:23](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py#L23); [packages/dbgpt-core/src/dbgpt/agent/skill/manage.py:1026](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/agent/skill/manage.py#L1026)
- Long-lived credentials (LLM key in the process environment, plaintext database passwords) are reachable by model-written code because every subprocess inherits the full server environment. (ASI03, LLM02, T9; C8) — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py:222](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py#L222); [packages/dbgpt-core/src/dbgpt/agent/skill/manage.py:1026](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/agent/skill/manage.py#L1026); [packages/dbgpt-serve/src/dbgpt_serve/datasource/manages/connect_config_db.py:42](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-serve/src/dbgpt_serve/datasource/manages/connect_config_db.py#L42)

## Criterion details

### C1 Identity & least privilege — 0.00 (high)

The web server's default network exposure and authentication are not locked down. The agent's tools run as the server's operating-system user with the server's full environment, including the LLM API key, and connect to databases with whatever stored credentials the datasource holds. There is no per-tool or per-request narrowing of authority, and no authorization layer between the agent and its tools.

- **S L0:** The agent acts with the server process's ambient authority: shell and Python run as the server user with the full os.environ. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py:222](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py#L222) (verified)
  - *To reach the next level:* No dedicated or scoped identity for the agent; L1 needs at least a dedicated identity separate from the server's own.
- **C L0:** No authorization layer sits between the agent and its tools; each tool uses the process's credentials directly, and subprocesses inherit the full environment. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py:222](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py#L222); [packages/dbgpt-core/src/dbgpt/agent/skill/manage.py:1026](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/agent/skill/manage.py#L1026) (verified)
  - *To reach the next level:* No tool path is checked against a scoped identity; L1 needs the main tool path to pass an authorization check.
- **D L0:** The default configuration provides no narrower identity, and its network exposure and authentication are not locked down. (verified)
  - *To reach the next level:* Least privilege requires manual hardening; L1 needs a narrower default.
- **B L0:** A hijacked agent holds the server user's whole account: shell, files, network, the LLM key, and every connected database's credentials. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py:23](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py#L23); [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py:222](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py#L222); [packages/dbgpt-serve/src/dbgpt_serve/datasource/manages/connect_config_db.py:42](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-serve/src/dbgpt_serve/datasource/manages/connect_config_db.py#L42) (verified)
  - *To reach the next level:* Authority reaches the full host account plus connected databases; L1 needs it confined to write access on a limited set of systems.
- **Cap:** none

### C2 Approval gates — 0.20 (high)

The only human approval in the agent path is a confirmation prompt for connector (MCP) tools that a catalog marks as writes. Shell commands, Python, SQL, and skill scripts never require approval. The connector approval gate is not a strict boundary.

- **S L2:** Per-call confirmation for catalog-listed connector write tools, showing a repr of the arguments with secret-named keys masked. — [packages/dbgpt-core/src/dbgpt/agent/resource/connector/confirmation.py:67-78](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/agent/resource/connector/confirmation.py#L67-L78); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:1972-1976](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L1972-L1976) (verified)
  - *To reach the next level:* No argument-level policy and the approval channel is not bound to the requesting principal; L3 also needs the exact call rendered with risk tiers covering all consequential tools.
- **C L0:** The most powerful tools (shell_interpreter, code_interpreter, sql_query, execute_skill_script_file) are never gated, and the connector gate is not a strict boundary. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:2913-2922](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L2913-L2922); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:3011](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L3011) (verified)
  - *To reach the next level:* The shell and code tools are exempt; L1 needs at least every flagged mutating tool gated on every path.
- **D L1:** The gate is on for catalog connectors, but its enforcement is not tied to the human principal, so approval can be satisfied by a non-principal. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py:23](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py#L23) (verified)
  - *To reach the next level:* Approval can be satisfied by a non-principal; L2 needs approval that the model or tool output cannot grant.
- **B L0:** Ungated actions include arbitrary shell on the host, DML/DDL through the SQL connector, and outbound HTTP, none with undo. — [packages/dbgpt-core/src/dbgpt/datasource/rdbms/base.py:628-631](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/datasource/rdbms/base.py#L628-L631); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py:23](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py#L23) (verified)
  - *To reach the next level:* Irreversible deletes and external sends happen without checkpoints; L1 needs at least some actions to be reversible.
- **Cap:** C2-SELFAPPROVE — Approval-gate enforcement is not tied to the human principal, so the model can satisfy approval.

### C3 Tool & action scoping — 0.15 (high)

The default tool set hands the model a raw shell, raw Python, and a SQL tool, all running on the server host. The SQL tool's 'SELECT only' rule is not a strict boundary and the connector beneath it executes writes and DDL. A few tools validate properly (read_file resolves real paths against an allowlist), but the skill script runner's path handling is not a complete boundary, and the shell tool makes every other check moot.

- **S L1:** Denylist filtering only: SQL and bash are filtered by denylists; read_file alone uses realpath containment. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/utils.py:181-191](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/utils.py#L181-L191); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/read_file.py:55](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/read_file.py#L55) (verified)
  - *To reach the next level:* Validation is denylist-based and the shell is raw passthrough; L2 needs typed validation across tools.
- **C L1:** Only read_file, the html template path and sql_query validate inputs; shell, Python and execute_skill_script_file do not. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:2913-2922](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L2913-L2922) (verified)
  - *To reach the next level:* Most built-in tools don't validate; L2 needs most built-in tools validated.
- **D L0:** Every tool, including shell, Python, SQL and sub-agent dispatch, is enabled by default in full mode. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:2913-2922](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L2913-L2922) (verified)
  - *To reach the next level:* Exec, write and network tools are all on by default; L1 needs dangerous tools to be individually disableable.
- **B L0:** A misused shell or Python tool can run any command against the whole host and any reachable network host. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py:23](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py#L23); [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py:25](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py#L25) (verified)
  - *To reach the next level:* General-purpose tools reach the whole machine; L1 needs at least minor limits on reach.
- **Cap:** none

### C4 Code-execution isolation — 0.42 (high)

By default, model-written Python and shell commands run as ordinary subprocesses on the server host, with the server's full environment (including the LLM API key) and unrestricted network access; Python code checks are explicitly switched off and the bash check is a short denylist. Docker, Podman and nerdctl backends exist and fail closed if selected, but they are off unless SANDBOX_RUNTIME is set, use a stock root container with networking on, and the skill script runner always executes on the host regardless of the setting.

- **default configuration** (default; raw 0.00 → 0.00)
  - **S L0:** The default LocalRuntime launches a same-user host subprocess; Python validation is disabled and bash gets only a substring denylist. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py:25](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py#L25); [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py:217-222](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py#L217-L222); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/_execution.py:92](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/_execution.py#L92) (verified)
    - *To reach the next level:* No isolation primitive by default; L1 needs at least filtering on the main (Python) path.
  - **C L0:** No execution path is sandboxed in the default configuration. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py:25](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py#L25) (verified)
    - *To reach the next level:* No path is sandboxed by default; L1 needs the main exec tool sandboxed.
  - **D L0:** Container execution is opt-in: an unset SANDBOX_RUNTIME selects local execution even when Docker is installed. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/config.py:40-42](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/config.py#L40-L42); [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py:25](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py#L25) (verified)
    - *To reach the next level:* Isolation is off by default; L1 needs it on by default.
  - **B L0:** Code runs on the host with dict(os.environ) passed in, so API keys, the home directory and the network are all reachable. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py:222](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py#L222) (verified)
    - *To reach the next level:* Credentials are in the execution environment; L1 needs credentials kept out of the subprocess.
- **opt-in Docker runtime (SANDBOX_RUNTIME=docker)** (alt; raw 0.42, cap G1 → 0.42) ← counted
  - **S L2:** A per-call stock container from python:3.11-slim (root, default capabilities) with memory and CPU limits. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/docker_runtime.py:48-58](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/docker_runtime.py#L48-L58); [packages/dbgpt-sandbox/src/docker_images/Dockerfile.agent:1](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/docker_images/Dockerfile.agent#L1) (verified)
    - *To reach the next level:* No non-root user, dropped capabilities, seccomp or read-only root; L3 needs a hardened container profile.
  - **C L1:** shell, Python and execute_analysis go through run_code, but execute_skill_script_file always spawns a host subprocess with the full environment. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/_execution.py:95](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/_execution.py#L95); [packages/dbgpt-core/src/dbgpt/agent/skill/manage.py:1026](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/agent/skill/manage.py#L1026) (verified)
    - *To reach the next level:* Skill scripts run on the host; L2 needs most paths sandboxed with only low-power exceptions.
  - **D L2:** Selected via an environment variable; a configured container backend that fails to start raises instead of falling back to local. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py:49-52](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py#L49-L52); [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/config.py:42](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/config.py#L42) (verified)
    - *To reach the next level:* Enabled and disabled by an env var without a warning; L3 needs an explicit, loudly named operator flag to disable.
  - **B L2:** Workspace files are copied in and the container is removed per call with only explicit env vars, but network_disabled defaults to False. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/base.py:57](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/base.py#L57); [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/docker_runtime.py:55](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/docker_runtime.py#L55) (verified)
    - *To reach the next level:* Network egress is unrestricted; L3 needs egress off or allowlisted.
- **Cap:** G1 — Opt-in mechanism: off in the scored default configuration.

### C5 Untrusted input blast radius — 0.00 (high)

The agent reads untrusted content (uploaded files, knowledge-base documents, database rows, MCP connector results, and anything it fetches with curl) into the same context that chooses its tools, with nothing to separate data from instructions. In the same session it holds database credentials and the LLM key, can run shell commands, and can send data anywhere on the network, all without human approval.

- **S L0:** No structural limit after untrusted content is read; shell, Python and SQL stay available without approval. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:2913-2922](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L2913-L2922); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:2400](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L2400) (verified)
  - *To reach the next level:* No mechanism limits a hijacked agent; L1 needs at least detection or marking of untrusted content.
- **C L0:** Tool results, file contents and connector outputs enter context with the same standing as the user's request. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:3011](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L3011) (verified)
  - *To reach the next level:* Untrusted sources are not distinguished; L1 needs at least one source handled.
- **D L0:** No control exists to be on by default. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:2913-2922](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L2913-L2922) (verified)
  - *To reach the next level:* Nothing to enable; L1 needs a control on by default.
- **B L0:** A hijacked agent can exfiltrate secrets and data via curl and take irreversible actions (DROP via SQL, rm via shell) with no human involved, across users who share the server. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py:23](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py#L23); [packages/dbgpt-core/src/dbgpt/datasource/rdbms/base.py:628-631](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/datasource/rdbms/base.py#L628-L631); [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py:222](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py#L222) (verified)
  - *To reach the next level:* Leak and irreversible action are both unattended; L1 needs one of them to require a human.
- **Cap:** C5-PUBLICTRIGGER — The default server's network exposure and authentication are not locked down, so outside parties can instruct an agent holding write credentials.

### C6 Memory, context & configuration integrity — 0.05 (medium)

Skills are folders of instructions and scripts on disk; when one is loaded its SKILL.md is injected into the system prompt with an order to follow it strictly, and the agent's unsandboxed shell can write new skill folders into that same directory, which serves every user. Past conversation turns are reloaded into later rounds, and knowledge-base documents feed retrieval. Conversations are keyed by a user name, and skills and knowledge spaces are shared.

- **S L0:** Skill instructions load as high-priority context ('strictly follow'), and nothing stops the host shell from writing a new skill into the shared skills directory. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:2444](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L2444); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/skill_tools.py:44](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/skill_tools.py#L44); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py:23](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py#L23) (inferred)
  - *To reach the next level:* No validation or gating of writes to persistent instructions; L1 needs at least logged writes.
- **C L0:** No memory, skill or knowledge path is controlled. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:2400](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L2400) (verified)
  - *To reach the next level:* No store is controlled; L1 needs at least one store controlled.
- **D L1:** Conversations are tied to dialogue.user_name, but the identity behind it is not strongly authenticated; skills are global. (verified)
  - *To reach the next level:* Isolation does not rest on a verified identity; L2 needs per-user namespaces enforced from an authenticated identity.
- **B L0:** A poisoned skill persists across sessions and users and can drive shell and SQL tool use. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:2444](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L2444) (inferred)
  - *To reach the next level:* Poisoned context persists across users and triggers tools; L1 needs it confined to one user's sessions.
- **Cap:** none

### C7 Third-party extensions — 0.00 (high)

The shell tool's own description invites the model to run pip, apt, and curl, so the agent can install and execute third-party packages on the host whenever it decides to, without asking. Skills imported from GitHub are fetched from a branch tip with no pinning or integrity check, and their scripts run as host subprocesses with the server's full environment. MCP connectors are remote servers the user adds explicitly; custom connectors bypass the catalog entirely.

- **S L0:** Model-chosen package installs are possible (and advertised) through the host shell; GitHub skills are downloaded from a branch zip with no hash or signature. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py:23](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py#L23); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:947-953](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L947-L953) (verified)
  - *To reach the next level:* Remote code is executed unverified; L1 needs extension sources to be user-chosen rather than model-chosen.
- **C L0:** No extension type (packages, skills, MCP connectors) is verified. — searched `rg -n -i 'sha256|hashlib|signature|checksum'` in `packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py` → 0 hits (no integrity check anywhere in the skill import/upload code) (verified)
  - *To reach the next level:* Nothing is verified; L1 needs at least one extension type verified.
- **D L0:** Packages can be installed by the model with no consent; skill import is explicit but does not show what will run. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py:23](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py#L23) (verified)
  - *To reach the next level:* Installs happen automatically at the model's request; L1 needs at least a consent prompt.
- **B L0:** Skill scripts and pip-installed code run on the host as the server user with os.environ copied in. — [packages/dbgpt-core/src/dbgpt/agent/skill/manage.py:1026](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/agent/skill/manage.py#L1026); [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py:222](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py#L222) (verified)
  - *To reach the next level:* Extensions get the full environment and credentials; L1 needs a separate process at minimum plus scrubbed credentials for L2.
- **Cap:** C7-RCELOAD — By default the agent can pip/apt-install and run remote packages on the host at the model's own request, with no consent step.

### C8 Secrets & sensitive-data protection — 0.20 (high)

The setup wizard writes its config, which can hold the LLM API key, to a file created with owner-only permissions, and secret-named arguments are masked in approval prompts. Elsewhere, database passwords are stored as plain text in the metadata database, connector-credential encryption is not robust, and every code and skill subprocess receives the server's full environment, so the model can read any key it wants. A local tracer records LLM replies and tool results by default; there is no third-party telemetry.

- **S L1:** Secrets come from env or a 0600 config file; masking exists only in the approval args summary and privacy-tagged config fields. — [packages/dbgpt-core/src/dbgpt/cli/_config.py:41](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/cli/_config.py#L41); [packages/dbgpt-core/src/dbgpt/agent/resource/connector/confirmation.py:95](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/agent/resource/connector/confirmation.py#L95); [packages/dbgpt-serve/src/dbgpt_serve/datasource/manages/connect_config_db.py:42](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-serve/src/dbgpt_serve/datasource/manages/connect_config_db.py#L42) (verified)
  - *To reach the next level:* No type-level masking or log filter on main paths; L2 needs redaction on the main logging paths.
- **C L1:** Only the approval summary path masks secrets; subprocess environments, tracer spans and model-bound tool output are unprotected. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py:222](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py#L222); [packages/dbgpt-core/src/dbgpt/agent/core/base_agent.py:686-688](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/agent/core/base_agent.py#L686-L688) (verified)
  - *To reach the next level:* Logs, transcripts and subprocess env are unprotected; L2 needs logs and transcripts covered.
- **D L1:** No telemetry, but the tracer is on by default and stores full LLM replies and action reports; credential-encryption defaults are not robust. — [packages/dbgpt-app/src/dbgpt_app/dbgpt_server.py:283-292](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/dbgpt_server.py#L283-L292) (verified)
  - *To reach the next level:* Payload logging is on by default and unredacted; L2 needs reasonable logging defaults.
- **B L0:** Long-lived LLM keys and database passwords are reachable by the model through every code subprocess. — [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py:222](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/local_runtime.py#L222); [packages/dbgpt-core/src/dbgpt/agent/skill/manage.py:1026](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/agent/skill/manage.py#L1026) (verified)
  - *To reach the next level:* Long-lived high-privilege keys reach every subprocess; L1 needs keys out of the model's reach.
- **Cap:** none

### C9 Audit & traceability — 0.40 (high)

A tracer that is on by default writes a span for every agent action, including the model's reply and the tool output, to a local JSONL file and an SQLite store, and the conversation history with every step is saved at the end of each turn. These records do not reliably say who asked, approvals are not recorded, spans are batched and flushed late, and everything sits on the same host the agent's unsandboxed shell can edit.

- **S L2:** Structured per-action spans (agent.generate_reply.act with llm_reply and action_report) with timestamps. — [packages/dbgpt-core/src/dbgpt/agent/core/base_agent.py:666-688](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/agent/core/base_agent.py#L666-L688) (verified)
  - *To reach the next level:* No reliable actor attribution, no approver; L3 needs principal and approver attribution.
- **C L2:** Main and sub-agent actions (both ReActAgent subclasses) produce act spans; connector approvals and denials are not logged. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/subagent/dispatcher.py:391](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/subagent/dispatcher.py#L391) (verified)
  - *To reach the next level:* Approvals and denials are not recorded; L3 needs them alongside every tool call.
- **D L1:** On by default, written to logs/ and SQLite under the server directory, which the agent's host shell can edit or delete. — [packages/dbgpt-app/src/dbgpt_app/dbgpt_server.py:283-292](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/dbgpt_server.py#L283-L292); [packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py:25](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-sandbox/src/dbgpt_sandbox/sandbox/execution_layer/runtime_factory.py#L25) (verified)
  - *To reach the next level:* Records are writable by the agent's own tools; L2 needs storage the agent's tools can't reach.
- **B L1:** Spans are queued and flushed in batches of 10 or every 10 seconds; history is persisted only at turn end. — [packages/dbgpt-core/src/dbgpt/util/tracer/span_storage.py:32-33](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/util/tracer/span_storage.py#L32-L33) (verified)
  - *To reach the next level:* Records are flushed late; L2 needs per-action flush.
- **Cap:** none

### C10 Limits & kill switch — 0.45 (high)

The main agent is capped at 30 reasoning steps, shell commands at 30 seconds, Python at 60 seconds, and each sub-agent at 15 steps and 10 minutes, with at most three sub-agents per dispatch and no nested dispatch. There is no token or cost cap and no overall time limit, and each dispatch hands sub-agents fresh budgets. Closing the stream cancels the agent and kills the local process tree, but the skill script runner leaves its subprocess running when it times out.

- **S L2:** Iteration cap (30) plus per-execution timeouts enforced in code. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:3029](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L3029); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py:54](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/tools/shell_interpreter.py#L54); searched `rg -n -i 'max_cost|cost_limit|spend_limit|budget_usd|max_total_tokens'` in `packages/dbgpt-app/src/dbgpt_app/openapi/api_v1 packages/dbgpt-core/src/dbgpt/agent/core packages/dbgpt-core/src/dbgpt/agent/expand` → 0 hits (no cost or token budget in the agent loop) (verified)
  - *To reach the next level:* No token/cost cap or session wall-clock; L3 needs step, time and cost caps together.
- **C L2:** Top-level loop plus tool timeouts; sub-agents get their own 15-step/600 s budgets rather than drawing from the parent's. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/subagent/dispatcher.py:44-47](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/subagent/dispatcher.py#L44-L47); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/subagent/dispatcher.py:557](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/subagent/dispatcher.py#L557) (verified)
  - *To reach the next level:* Sub-agents don't count against the parent budget; L3 needs one shared budget.
- **D L2:** Sensible hard-coded defaults; max_parallel_subagents is operator-configurable. — [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:2501](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L2501) (verified)
  - *To reach the next level:* The model can obtain fresh budgets by dispatching repeatedly; L3 needs limits it can't reset by delegating.
- **B L1:** Stopping cancels the agent task and kills local process trees, but execute_skill_script_file leaves its host subprocess running after its 120 s timeout. — [packages/dbgpt-core/src/dbgpt/agent/skill/manage.py:1039](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-core/src/dbgpt/agent/skill/manage.py#L1039); [packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:1111](https://github.com/eosphoros-ai/DB-GPT/blob/5905245a6750bafa636aa36a904b7fd4ead75334/packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py#L1111) (verified)
  - *To reach the next level:* Work can be orphaned after a stop or timeout; L2 needs stops to leave nothing running.
- **Cap:** none

## Rule-of-Two check
[A] untrusted input: Uploaded files, knowledge documents, DB rows, MCP results and curl output enter context (agentic_data_api.py:2400, tools/shell_interpreter.py:23) · [B] sensitive data/systems: Full server env incl. LLM key in every code subprocess (local_runtime.py:222); stored DB credentials (connect_config_db.py:42) · [C] state change / egress: Host shell/Python and SQL writes with no approval (agentic_data_api.py:2913-2922, rdbms/base.py:631) · Same default session? Yes

## Highest-impact improvements
1. Make a hardened container runtime the default (non-root, no network, no host env) and route execute_skill_script_file through it. — C4 D L0→L3, +0.150 before caps (Playbook 3)
2. Harden the generated server configuration's network exposure and authentication defaults. — C1 D L0→L2, +0.100 before caps (Playbook 4)
3. Stop passing os.environ to code and skill subprocesses; pass only the explicit per-call variables. — C8 B L0→L2, +0.100 before caps (Playbook 4)
4. Gate shell, Python, SQL writes and all connector calls behind per-call human approval tied to the authenticated requester. — C2 C L0→L2, +0.150 before caps (Playbook 5)
5. Enforce read-only SQL with a parser or a read-only database role. — C3 S L1→L3, +0.150 before caps (Playbook 3)

## Re-audit log
- No changes.

## Limitations
- Static source review of the pinned commit only; nothing was executed, installed, or probed.
- Scope was the ReAct data agent path (agentic_data_api.py, tools/, subagent/, dbgpt-sandbox, skill manager, connector confirmation). Older AWEL/flow, dbgpts hub, plugin_hub, the web frontend and the libro notebook service were not reviewed in depth.
- Some approval-gate findings and the model writing new skills through the host shell are reasoned from verified code paths, not observed.
- Local HuggingFace models default to trust_remote_code=True (packages/dbgpt-core/src/dbgpt/model/adapter/hf_adapter.py:124); this was not scored because the default profile uses a proxy API model.
- No reviewer-injection text was found (no AGENTS.md/CLAUDE.md; no text aimed at AI reviewers).
