Back to skill

Security audit

Knowledge Graph - Graph Template Query Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent graph-query template helper with no hidden execution, persistence, or data collection, but users should validate generated query structure before production use.

Install only if you are comfortable treating the output as starter code. Before using generated Cypher or SPARQL in an application, validate or allowlist labels, relationship types, property names, operators, predicates, and traversal depth, and avoid copying the sensitive-data examples without proper authorization, minimization, auditing, and access controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/query_template_generator.py:231
Finding

Unvalidated Structural Query Interpolation Enables Cypher and SPARQL Injection

Content
View full analysis
(b:{target}) RETURN a, b LIMIT $limit""" ``` ```python return QueryTemplate( name=f"sparql_{source}_{rel_type}", query=f"""PREFIX ex: SELECT ?source ?target WHERE {{ ?source ex:{rel_type} ?target . }} LIMIT $limit""", language=language, parameters=[Parameter("limit", "integer", "Result limit", default_value=100)] ) ``` ```python query = f"""MATCH path = (start:{start})-[*1..{max_depth}]-(end:{end}) RETURN path, LENGTH(path) as hops LIMIT $limit""" ``` ```python return QueryTemplate( name=f"sparql_paths_{start}_{end}", query=f"""PREFIX ex: SELECT ?path WHERE {{ ?start a ex:{start} ; ex:connects* ?end . ?end a ex:{end} . }} LIMIT $limit""", language=language ) ``` ```python query = f"""MATCH (s:{source})-[:{rel}]->(t:{target}) RETURN t.{group_by}, COUNT(s) as count GROUP BY t.{group_by} ORDER BY count DESC LIMIT $limit""" ``` ```python return QueryTemplate( name=f"sparql_aggregate_{source}", query=f"""PREFIX ex: SELECT ?category (COUNT(?item) AS ?count) WHERE {{ ?item a ex:{source} ; ex:{rel} ?category . }} GROUP BY ?category ORDER BY DESC(?count) LIMIT $limit""", language=language ) ``` ```python query = f"""MATCH (n:{label}) WHERE n.{property_name} {operator} $value RETURN n LIMIT $limit""" ``` ```python return QueryTemplate( name=f"sparql_filter_{label}", query=f"""PREFIX ex: SELECT ?en ...[truncated 3907 chars]
Remediation
View remediation
", "gt": ">", "gte": ">=", "lt": "<", "lte": "<=", } ``` - Never insert an arbitrary operator string supplied by a caller. 3. **Constrain traversal depth** - Require an actual integer rather than accepting arbitrary string formatting. - Reject booleans and non-integer values. - Apply conservative bounds, for example: ```python if not isinstance(max_depth, int) or isinstance(max_depth, bool): raise TypeError("max_depth must be an integer") if not 1 <= max_depth <= 4: raise ValueError("max_depth must be between 1 and 4") ``` 4. **Use safe identifier quoting where supported** - Apply the target database driver's official identifier-escaping mechanism after validation. - Do not treat quoting alone as sufficient; schema allowlisting remains preferable. - For SPARQL, construct IRIs through an RDF/SPARQL library rather than concatenating fragments into query text. 5. **Separate trusted schema configuration from user data** - Accept user-provided values only through database parameters. - Resolve user-facing choices to internally defined labels, relationships, predicates, and operators. - Avoid exposing raw query-structure arguments in public API endpoints. 6. **Strengthen template validation** - Extend ...[truncated 1039 chars]
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description says the skill generates reusable Cypher or SPARQL query templates for common graph operations. However, the provided code does not generate queries or templates. Its primary function is registry management: registering templates, retrieving them, searching/filtering them, tracking metadata, ratings and usage, managing versions, and importing/exporting JSON. While the example data includes Cypher templates, that is sample content rather than generation behavior. This is a material description-behavior mismatch because the actual code is a template storage/management subsystem, not a query-template generator.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example request "Create a reusable graph query." is broad and lacks constraints on database type, task scope, or template intent. In a markdown skill description, this kind of generic phrasing can cause unintended invocation because it overlaps with ordinary requests for graph-query help rather than a narrowly defined template-generation skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The social-network examples return user email addresses for friends and second-degree connections without any privacy warning or minimization guidance. In this skill context, reusable templates are likely to be copied into applications, so exposing direct contact data by default can enable unnecessary disclosure or user-enumeration patterns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The healthcare examples expose patient identifiers, names, ages, conditions, and provider relationships and label the templates as production-ready without any privacy, authorization, or minimum-necessary-use guidance. In a reusable query-template skill, this can encourage deployment of sensitive-data access patterns without access control or compliance safeguards, increasing risk of PHI leakage.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file explicitly promotes parameterized queries as a best practice, but the template composition example builds a query by string concatenation. In a query-generation skill, this normalizes unsafe composition patterns that can lead to Cypher/SPARQL injection or broken query semantics if any composed fragment is influenced by user input.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The SPARQL example filters results with LANG(?label) = $lang and the accompanying parameters set lang to en. This presents English as the default locale behavior without any nearby guidance to let users opt in to another language or explanation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This is a true issue. The document repeatedly presents Cypher and SPARQL templates that substitute labels, property names, operators, relationship types, and class/property identifiers directly into query structure while later claiming that all dynamic values are parameterized. In graph query languages, structural elements usually cannot be safely parameterized the same way as literal values, so consumers may implement unsafe string interpolation and become vulnerable to query injection, authorization bypass, or destructive query execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says this skill generates query templates for common graph database operations. In this file, the code stores, indexes, rates, versions, imports, exports, and prints statistics about templates, but does not generate Cypher or SPARQL templates from user intent or graph operations. This is a semantic mismatch between the declared skill purpose and the implemented behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

The best-practices section at L496 says all templates include LIMIT clauses. This is contradicted by the SPARQL example at L180-L194 ('Find Papers by Author'), which ends with ORDER BY DESC(?year) and includes no LIMIT clause despite listing a limit parameter at L196-L201.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

L501 asserts 'Error Handling - Ready for null/invalid inputs', but this file only contains static query templates and simple usage snippets. There is no validation, fallback behavior, or exception handling shown anywhere in the examples, so the documentation overstates what the code/document actually demonstrates.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This Python file contains example templates with the language field fixed to "cypher", which imposes a specific language/locale choice in natural-language-visible data. The file does not offer an alternative language selection or explain that the skill is intentionally limited to Cypher for a graph-database-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.