Knowledge Graph - Csv Graph Loader Generator

Security checks across malware telemetry and agentic risk

Overview

This appears to be a purpose-aligned graph data generation skill with a documentation gap around downstream writes, not hidden or malicious behavior.

Review generated Neo4j loaders, RDF mappings, and import configs before running them, especially against production databases. Use least-privilege database credentials, confirm target paths and database names, and prefer a test database or backup when importing data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill explicitly generates Neo4j import scripts, RDF mappings, and loader outputs that are meant to be executed against downstream graph systems, but it does not warn that using those outputs can create or modify data and files. This is a real safety/documentation gap because users may treat generated loaders as passive artifacts rather than write-capable instructions, increasing the chance of unintended imports or environment changes.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal