Back to skill

Security audit

Knowledge Graph - Janusgraph Connector

Security checks for vulnerabilities and agentic risk

Overview

The skill is a JanusGraph database helper, but it presents destructive graph operations and unsafe query patterns as production-ready without enough safeguards or warning.

Review this skill carefully before installing. Use it only with test or least-privilege JanusGraph credentials, treat all delete examples as destructive, require explicit confirmation before drop() or bulk mutation operations, and do not rely on the advertised parameter binding until the connector uses a real Gremlin binding or bytecode API with validation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/janusgraph_connector.py:312
Finding

Gremlin Query Injection Through Unescaped String Interpolation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/janusgraph_connector.py:235
Finding

Query Parameters Are Accepted but Never Bound or Validated

Content
View full analysis
QueryResult: """ Execute a Gremlin query. Args: query: Gremlin query string params: Optional parameters for parameterized query Returns: QueryResult with records and metadata """ if not self.is_connected(): error_msg = "Not connected to JanusGraph" self.logger.error(error_msg) return QueryResult(records=[], success=False, error=error_msg) try: start_time = datetime.now() # Validate query if not query or not isinstance(query, str): raise ValueError("Invalid query") self.logger.debug(f"Executing query: {query[:100]}...") # Simulate query execution (in real impl, would execute actual Gremlin) # For demo: parse and execute mock query records = self._mock_query_execution(query, params) execution_time = (datetime.now() - start_time).total_seconds() * 1000 self.stats.queries_executed += 1 self.stats.last_query_time = datetime.now() result = QueryResult( records=records, success=True, execution_time_ms=execution_time ) self.logger.debug(f"Query executed in {execution_time:.2f}ms, returned {len(records)} records") return result except Exception as e: self.logger.error(f"Query execution failed: {e}") return QueryResult(records=[], success=False, error=str(e)) def _mock_query_execution(self, query: str, params: Optional[List[Any]]) -> List[Dict[str, Any]]: """Mock query execution for demonstration""" # This w ...[truncated 2637 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
README.md:20
Finding

Unpinned Third-Party Dependencies Produce Non-Reproducible Installations

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Unvalidated Output Injection

High
Category
Output Handling
Confidence
100% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · scripts/janusgraph_connector.py (reported line 412)May include surrounding context.

python
self.logger.info(f"Updated vertex {vertex_id}")
            return True
        else:
            self.logger.error(f"Update failed: {result.error}")
            return False

    def delete_vertex(self, vertex_id: str) -> bool:

Unvalidated Output Injection

High
Category
Output Handling
Confidence
100% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · scripts/janusgraph_connector.py (reported line 435)May include surrounding context.

python
self.logger.info(f"Deleted vertex {vertex_id}")
            return True
        else:
            self.logger.error(f"Delete failed: {result.error}")
            return False

    def batch_create_vertices(self, vertices: List[Dict[str, Any]]) -> int:

Unvalidated Output Injection

High
Category
Output Handling
Confidence
100% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · scripts/janusgraph_connector.py (reported line 593)May include surrounding context.

python
self.logger.info(f"Deleted edge from {from_id} to {to_id}")
            return True
        else:
            self.logger.error(f"Delete edge failed: {result.error}")
            return False

    # ========================================================================

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file advertises create, update, and delete graph operations, including deleting vertices and edges, but does not include any user-facing warning about potential data loss, mutation of production graphs, or the need to use caution with destructive actions. For markdown files, the skill description should warn when behavior can affect user data or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly documents destructive Gremlin operations such as dropping vertices and edges, but provides no adjacent warning about irrecoverable data loss, environment scoping, backups, or confirmation requirements. In an agent setting, this increases the chance that a user or downstream automation will execute deletion commands against production graph data without understanding the blast radius.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file includes direct vertex deletion patterns using drop() and a Python example that executes the deletion, but the surrounding description only says 'Remove a vertex from the graph' and does not warn that the action is destructive and may permanently remove data. Under the markdown criteria for missing user warnings, examples that affect user data or system integrity should disclose the risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The pattern 'Delete Multiple Vertices' shows a batch drop() operation against all vertices with a label, which can remove large amounts of data, but the markdown provides no caution about irreversibility or scope verification. This omission is safety-relevant because the skill description presents destructive behavior without warning about its impact on stored data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code provides a vertex deletion method that executes a drop operation against the graph, but the method offers no confirmation prompt or user-facing warning about the destructive action. Although it logs success or failure afterward, there is no disclosure before the irreversible operation occurs in the method itself or its docstring.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The delete_edge method issues a .drop() query that removes relationships from the graph, but the method contains no confirmation step or warning that the action is destructive. Existing logging only reports the action after execution and does not serve as advance disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file documents graph examples containing personal data attributes such as email, age, location, salary, and purchase history, and includes concrete sample identities and emails. Because the skill description presents these examples as production-ready and does not warn readers about privacy considerations or the need to anonymize real user data, it lacks user-facing disclosure for data-sensitive behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The import/export section documents reading data.graphson and writing export.graphson, which can modify local state and expose or overwrite graph data, but there is no warning about file-system effects, destination sensitivity, or backup/privacy considerations. For markdown files, behaviors that affect user data or system integrity should be disclosed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.