T09 · Insecure Skill Coding Practices
- Location
scripts/janusgraph_connector.py:312- Finding
Gremlin Query Injection Through Unescaped String Interpolation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a JanusGraph database helper, but it presents destructive graph operations and unsafe query patterns as production-ready without enough safeguards or warning.
Review this skill carefully before installing. Use it only with test or least-privilege JanusGraph credentials, treat all delete examples as destructive, require explicit confirmation before drop() or bulk mutation operations, and do not rely on the advertised parameter binding until the connector uses a real Gremlin binding or bytecode API with validation.
scripts/janusgraph_connector.py:312Gremlin Query Injection Through Unescaped String Interpolation
scripts/janusgraph_connector.py:235Query Parameters Are Accepted but Never Bound or Validated
README.md:20Unpinned Third-Party Dependencies Produce Non-Reproducible Installations
Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.
self.logger.info(f"Updated vertex {vertex_id}")
return True
else:
self.logger.error(f"Update failed: {result.error}")
return False
def delete_vertex(self, vertex_id: str) -> bool:
Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.
self.logger.info(f"Deleted vertex {vertex_id}")
return True
else:
self.logger.error(f"Delete failed: {result.error}")
return False
def batch_create_vertices(self, vertices: List[Dict[str, Any]]) -> int:
Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.
self.logger.info(f"Deleted edge from {from_id} to {to_id}")
return True
else:
self.logger.error(f"Delete edge failed: {result.error}")
return False
# ========================================================================
This markdown file advertises create, update, and delete graph operations, including deleting vertices and edges, but does not include any user-facing warning about potential data loss, mutation of production graphs, or the need to use caution with destructive actions. For markdown files, the skill description should warn when behavior can affect user data or system integrity.
The skill explicitly documents destructive Gremlin operations such as dropping vertices and edges, but provides no adjacent warning about irrecoverable data loss, environment scoping, backups, or confirmation requirements. In an agent setting, this increases the chance that a user or downstream automation will execute deletion commands against production graph data without understanding the blast radius.
This markdown file includes direct vertex deletion patterns using drop() and a Python example that executes the deletion, but the surrounding description only says 'Remove a vertex from the graph' and does not warn that the action is destructive and may permanently remove data. Under the markdown criteria for missing user warnings, examples that affect user data or system integrity should disclose the risk.
The pattern 'Delete Multiple Vertices' shows a batch drop() operation against all vertices with a label, which can remove large amounts of data, but the markdown provides no caution about irreversibility or scope verification. This omission is safety-relevant because the skill description presents destructive behavior without warning about its impact on stored data.
The code provides a vertex deletion method that executes a drop operation against the graph, but the method offers no confirmation prompt or user-facing warning about the destructive action. Although it logs success or failure afterward, there is no disclosure before the irreversible operation occurs in the method itself or its docstring.
The delete_edge method issues a .drop() query that removes relationships from the graph, but the method contains no confirmation step or warning that the action is destructive. Existing logging only reports the action after execution and does not serve as advance disclosure.
This markdown file documents graph examples containing personal data attributes such as email, age, location, salary, and purchase history, and includes concrete sample identities and emails. Because the skill description presents these examples as production-ready and does not warn readers about privacy considerations or the need to anonymize real user data, it lacks user-facing disclosure for data-sensitive behavior.
The import/export section documents reading data.graphson and writing export.graphson, which can modify local state and expose or overwrite graph data, but there is no warning about file-system effects, destination sensitivity, or backup/privacy considerations. For markdown files, behaviors that affect user data or system integrity should be disclosed.
No suspicious patterns detected.