Back to skill

Security audit

Knowledge Graph - Causal Chain Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local graph-analysis helper, with a performance caution for very large or adversarial graphs.

Install only if you need causal or dependency graph analysis. Use reasonable max_depth and confidence thresholds, avoid feeding untrusted huge graphs without external resource limits, and treat outputs as analytical guidance rather than automatic remediation instructions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/causal_chain_analyzer.py:484
Finding

Unbounded Breadth-First Traversal Enables Resource Exhaustion

Content
View full analysis
= self.config.max_depth: continue # Check confidence threshold if conf < confidence_threshold: continue incoming = self.reverse_edges.get(node, {}) if not incoming: # Root cause found chains.append(CausalChain( path=path[::-1], confidence=conf )) else: for source, edges in incoming.items(): for edge in edges: edge_conf = edge.get('confidence', 0.5) new_conf = conf * edge_conf if new_conf >= confidence_threshold: queue.append((source, path + [source], new_conf)) ``` ### Technical Analysis The `_find_root_causes_bfs` traversal accepts caller-provided graph structures and enqueues every eligible predecessor path. Each queue entry contains a newly copied path through `path + [source]`, causing both the number and cumulative size of allocated objects to increase rapidly on dense or highly branching graphs. Although `visited_at_depth` is declared, it is never used. The traversal therefore does not deduplicate equivalent states such as the same node reached at the same depth. It also does not prevent a node already present in the current path from being enqueued again, allowing cyclic graphs and self-loops to repeatedly expand until the configured depth limit is reached. The `max_results` configuration field is declared but is not ...[truncated 2018 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.