Back to skill

Security audit

Knowledge Graph - Csv Graph Loader Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent CSV-to-graph conversion helper, but generated database/import files should be reviewed before use.

Reasonable to install for CSV-to-graph prototyping. Treat generated Cypher, Turtle, and CSV as untrusted output: review it, test in a non-production database, validate or escape untrusted identifiers and values, and use least-privileged database credentials for imports.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/csv_loader.py:310
Finding

Unescaped Identifiers and Values Permit Cypher and RDF/Turtle Injection

Content
View full analysis
List[str]: """Generate Neo4j Cypher statements.""" statements = [] for entity_type, entity_def in self.entities.items(): # Find sample data sample_nodes = [n for n in self.nodes.values() if n.node_type == entity_type] if sample_nodes: sample = sample_nodes[0] stmt = f"MERGE (n:{entity_type} {{id: row.{entity_def.id_column}}})" for prop, value in sample.properties.items(): stmt += f"\nSET n.{prop} = row.{prop}" statements.append(stmt) for rel in self.relationships: stmt = f"MERGE (s:{rel.source_entity})-[:{rel.relationship_type}]->(t:{rel.target_entity})" statements.append(stmt) return statements def generate_triples(self, namespace: str = "http://example.org/") -> List[str]: """Generate RDF triple statements.""" triples = [] for node in self.nodes.values(): # Type triple node_uri = f"<{namespace}{node.node_id}>" type_uri = f"<{namespace}{node.node_type}>" triples.append(f"{node_uri} rdf:type {type_uri} .") # Property triples for prop, value in node.properties.items(): prop_uri = f"<{namespace}{prop}>" if isinstance(value, str): triples.append(f'{node_uri} {prop_uri} "{value}" .') else: triples.append(f"{node_uri} {prop_uri} {value} .") for edge in self.edges: source_uri = f"<{namespace}{edge.source_id}>" target_uri = f"<{namespace}{edge.target_id}>" rel_uri = f"<{namespace}{edge.edge_type}>" triples.append(f"{source_uri} {rel_uri} {target_uri} .") return triples ``` ### Technical Analysis The generator directly ...[truncated 2523 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/csv_loader.py:351
Finding

Unsafe Manual CSV Serialization Enables Record Injection and Spreadsheet Formula Injection

Content
View full analysis
Tuple[str, str]: """Convert to separate nodes.csv and edges.csv.""" # Generate nodes.csv nodes_lines = ["id,type"] for node in self.nodes.values(): for prop, value in node.properties.items(): if prop not in nodes_lines[0]: nodes_lines[0] += f",{prop}" for node in self.nodes.values(): line = f"{node.node_id},{node.node_type}" for prop in nodes_lines[0].split(",")[2:]: value = node.properties.get(prop, "") line += f",{value}" nodes_lines.append(line) # Generate edges.csv edges_lines = ["source,target,type"] for edge in self.edges: line = f"{edge.source_id},{edge.target_id},{edge.edge_type}" edges_lines.append(line) nodes_csv = "\n".join(nodes_lines) edges_csv = "\n".join(edges_lines) return nodes_csv, edges_csv ``` ### Technical Analysis The method constructs CSV output through direct string concatenation. It does not apply standard CSV quoting or escaping to headers or values. An attacker-controlled value containing a comma can create additional columns. A value containing carriage returns or line feeds can create new records. Quotes are not escaped according to CSV rules. Property names are also appended directly to the header and later parsed by splitting the header string on commas, so malicious property names can change both the schema and row serialization behavior. The method also leaves spreadsheet formula prefixes such as `=`, `+`, `-`, and `@` unchanged. If a generated file is opened by spreadsheet software, a malicious cell may be interpreted as a formula rather than text. The exact effects depend on the spreadsheet application and its security configuration. # ...[truncated 1273 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
70% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · examples/example-loaders.md (reported line 306)May include surrounding context.

entity_id,entity_name,entity_type,birth_date,profession,country,related_entity,relation_type E001,Marie Curie,Person,1867-11-24,Scientist,Poland,E002,MARRIED_TO E001,Marie Curie,Person,1867-11-24,Scientist,Poland,E003,DISCOVERED E002,Pierre Curie,Person,1859-05-15,Scientist,France,E001,MARRIED_TO E003,Radium,Chemical Element,,Element,Natural,E001,DISCOVERED_BY E004,Polonium,Chemical Element,,Element,Natural,E001,DISCOVERED_BY

text

### Generated RDF Knowledge Graph

```turtle

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
70% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · examples/example-loaders.md (reported line 324)May include surrounding context.

md
foaf:name "Marie Curie" ;
  dbo:birthDate "1867-11-24"^^xsd:date ;
  dbo:profession "Scientist" ;
  dbo:country ex:poland ;
  ex:marriedTo ex:pierre_curie ;
  ex:discovered ex:radium, ex:polonium ;
  rdfs:comment "Polish-born physicist" .

ex:radium a ex:ChemicalElement ;
  rdfs:label "Radium" ;
  ex:discoveredBy ex:marie_curie ;

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly generates Neo4j LOAD CSV scripts, RDF mappings, and other loader artifacts that are intended to import or transform data into graph systems, but it does not warn users that these outputs may perform writes or create import-ready configuration files. This omission can mislead users about the operational effect of generated artifacts, increasing the chance they execute database-modifying scripts without appropriate review, sandboxing, or least-privilege controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.