Back to skill

Security audit

Knowledge Graph - Graph Path Reasoning Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent graph-analysis helper with a real performance caveat around all-path enumeration, but no evidence of hidden access, exfiltration, persistence, or destructive behavior.

Reasonable to install for graph path analysis. Use explicit max path length and result limits, especially with large or user-supplied graphs, and validate generated explanations before relying on them for decisions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/graph_path_analyzer.py:219
Finding

Unbounded Graph Path Enumeration Can Cause Denial of Service

Content
View full analysis
List[GraphPath]: """ Find all paths between source and target. Args: source: Starting node target: Destination node max_paths: Maximum paths to return Returns: List of GraphPath objects """ paths = [] visited = set() def dfs(current, target_node, path, edges): if current == target_node: paths.append(GraphPath( nodes=path[:], confidence=self._calculate_confidence(path), edges=edges[:] )) return if len(path) - 1 >= self.config.max_path_length: return if max_paths and len(paths) >= max_paths: return for neighbor in self.edges.get(current, {}): if neighbor not in path: # Avoid cycles edge_data = self.edges[current][neighbor][0] # Check filters if not self._passes_filters(edge_data): continue path.append(neighbor) edge_obj = PathEdge( source=current, target=neighbor, relation_type=edge_data.get('type', 'connected_to'), confidence=edge_data.get('confidence', 0.5) ) edges.append(edge_obj) dfs(neighbor, target_node, path, edges) path.pop() edges.pop() dfs(source, target, [source], [] ...[truncated 3345 chars]
Remediation
View remediation
= effective_limit: return True if current == target_no ...[truncated 1025 chars]
Vulnerability Patterns
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Unbounded Output

Medium
Category
Output Handling
Confidence
90% confidence
Finding

The DFS all-paths routine allows max_length=None, enabling unbounded path enumeration on arbitrary graphs. In graph-analysis contexts, this can cause exponential blowup in CPU and memory usage, making denial-of-service feasible if an attacker controls the graph shape or query parameters.

Content

Scanner excerpt · references/graph-path-patterns.md (reported line 139)May include surrounding context.

Implementation:

python
def find_all_paths_dfs(graph, source, target, max_length=None):
    """
    Find all paths between source and target using DFS.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The class and method documentation state that the analyzer generates natural language explanations over graph relationships, implying explanations should reflect actual traversal semantics. However, _generate_explanation reads path.relation_types, which is never populated anywhere in the code, so explanations typically misdescribe every edge as connected_to rather than the real relation type.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring for find_path_bidirectional states Complexity: O(√(V + E)) - square root improvement, but the shown implementation is still a graph traversal over frontiers and does not support that stated bound from the code alone. This is an intent/documentation contradiction rather than a mere omission, because it explicitly promises a specific complexity behavior the implementation does not substantiate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.