Back to skill

Security audit

Knowledge Graph - Graph Query Optimization Assistant

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent graph-query optimization aid; its database-changing examples are advisory and user-directed, not hidden or automatic.

Review any suggested CREATE INDEX, CREATE CONSTRAINT, PROFILE, or benchmarking steps before applying them to a real graph database, especially production systems, because they can affect schema, performance, or workload. The skill itself does not appear to perform those actions automatically.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Unbounded Output

Medium
Category
Output Handling
Confidence
75% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · references/optimization-patterns.md (reported line 701)May include surrounding context.

Example:

cypher
-- Without size limit
MATCH (p:Person)-[:KNOWS]->(f:Person)
RETURN p, COLLECT(f) as friends

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The section labels one query as inefficient and the next as optimized, but both snippets are functionally identical. This is an active contradiction in the documentation rather than a mere omission, because the text explicitly claims an optimization that is not present.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.