Back to skill

Security audit

Graphql Builder

Security checks for vulnerabilities and agentic risk

Overview

This GraphQL helper is mostly purpose-aligned, but its shell script exposes unsafe arbitrary curl arguments that could read or write local files if a crafted URL argument is used.

Review this skill before installing. Use it only with trusted, simple file paths and trusted HTTPS GraphQL endpoints, and avoid letting untrusted text supply command arguments. The script should be fixed to use the shifted positional argument correctly, quote variables, pass -- before curl URLs, validate destinations, and document its required shell/network permissions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
" [ -f $2 ] && grep -q 'query\|mutation\|type' $2 && echo 'Valid GraphQL file' || echo 'Invalid' } cmd_format() { local file="${2:-}" [ -z "$file" ] && die "Usage: $SCRIPT_NAME format <file>" cat $2 2>/dev/null | sed 's/{/{ /g' | sed 's/}/ }/g' } cmd_introspect() { local url="${2:-}" [ -z "$url" ] && die "Usage: $SCRIPT_NAME introspect <url>" curl -s -X POST -H 'Content-Type: application/json' -d '{"query":"{__schema{types{name}}}"}' $2 2>/dev/null } cmd_schema() { local ...[truncated 3506 chars]:99
Finding

Curl Option Injection Enables Local File Exfiltration and Arbitrary File Overwrite

Content
View full analysis
" [ -f $2 ] && grep -q 'query\|mutation\|type' $2 && echo 'Valid GraphQL file' || echo 'Invalid' } cmd_format() { local file="${2:-}" [ -z "$file" ] && die "Usage: $SCRIPT_NAME format " cat $2 2>/dev/null | sed 's/{/{ /g' | sed 's/}/ }/g' } cmd_introspect() { local url="${2:-}" [ -z "$url" ] && die "Usage: $SCRIPT_NAME introspect " curl -s -X POST -H 'Content-Type: application/json' -d '{"query":"{__schema{types{name}}}"}' $2 2>/dev/null } cmd_schema() { local file="${2:-}" [ -z "$file" ] && die "Usage: $SCRIPT_NAME schema " cat $2 2>/dev/null | grep -E '^type |^input |^enum ' | head -20 } ``` ### Technical Analysis The user-controlled `$2` parameter is expanded without double quotes in commands including `curl`, `cat`, `grep`, and the shell file test. Bash consequently applies word splitting and pathname expansion to the supplied value. This is particularly dangerous in `cmd_introspect`. A value containing spaces is converted into multiple curl arguments, and words beginning with `-` are interpreted as curl options rather than as a URL. This is argument injection, not direct shell metacharacter command injection: injected shell operators are not reparsed, but arbitrary curl options can still substantially change the request. For example, an injected `--data-binary @` option can instruct curl to read a local file and include it in an outbound request. An injected `--output ` option can make curl write the response to an attacker-selected path. The dispatcher shifts the command name before invoking each handler, while the handlers incorrectly read `$2` rather than `$1` ...[truncated 2228 chars]
Remediation
View remediation
/dev/null`. Use `-sS`, check the exit status, set connection and transfer timeouts, and impose a response-size limit where practical. 7. Apply shell linting, such as ShellCheck, in continuous integration. Rules concerning unquoted expansions would identify each affected command. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill exposes shell-backed commands (scripts/script.sh ...) but does not declare any permissions or allowed-tools scope. That creates an authorization and transparency gap: consumers cannot tell up front that shell execution is required, and an agent framework may grant broader execution than intended. In a skill that accepts user-controlled inputs like file paths and URLs, undeclared shell capability increases the risk of unsafe command execution or misuse.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
80% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · scripts/script.sh (reported line 9)May include surrounding context.

sh
DATA_DIR="$HOME/.local/share/graphql-builder"
mkdir -p "$DATA_DIR"

#
#
#
#

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill claims to build and validate GraphQL artifacts, but it also performs live network GraphQL introspection against an arbitrary endpoint. That expands the trust boundary from local processing to outbound network activity, which can surprise users, leak metadata to external systems, and be abused to probe internal or sensitive GraphQL services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The introspection command posts to a fully user-supplied URL with no validation, restriction, or warning. In an agent or automation context, this creates arbitrary outbound HTTP capability that can be used for SSRF-style access to internal services, network reconnaissance, or contacting attacker-controlled endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code silently sends a POST request to the provided URL and suppresses errors, without any disclosure that external communication will occur. This reduces user awareness and oversight, making accidental data transmission or unauthorized network probing more likely in automated environments.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The curl invocation performs external transmission to an arbitrary destination, which is risky in a skill whose primary purpose is local GraphQL tooling. Even though the payload is a fixed introspection query, the capability still enables outbound communication and can be misused to interact with sensitive internal GraphQL endpoints.

Content

Scanner excerpt · scripts/script.sh (reported line 116)May include surrounding context.

sh
cmd_introspect() {
    local url="${2:-}"
    [ -z "$url" ] && die "Usage: $SCRIPT_NAME introspect <url>"
    curl -s -X POST -H 'Content-Type: application/json' -d '{"query":"{__schema{types{name}}}"}' $2 2>/dev/null
}

cmd_schema() {

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill states that data is stored in ~/.local/share/graphql-builder/ but does not explain what is persisted, how long it is retained, or whether sensitive content such as schemas, queries, tokens, or introspection results may be written there. This can lead to unintended retention of potentially sensitive API metadata on disk, especially on shared systems or developer workstations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.