Back to skill

Security audit

Knowledge Graph - Json To Triples Converter

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent JSON-to-RDF converter, but its bundled converter can emit unsafe RDF from crafted input, so it should be reviewed before production use.

Install only if you are comfortable treating the included converter as a prototype or internal-data utility. Do not use its Turtle or N-Triples output from untrusted JSON in a production RDF store unless you add standards-compliant literal escaping, URI encoding, datatype/language validation, and parser validation of the generated RDF.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/json_converter.py:51
Finding

RDF Triple Injection Through Unescaped Literals and Identifiers

Content
View full analysis
" elif self.language_tag: obj_str = f'"{self.obj}"@{self.language_tag}' elif self.data_type: obj_str = f'"{self.obj}"^^<{self.data_type}>' else: obj_str = f'"{self.obj}"' return f"{subject_str} {predicate_str} {obj_str} ." ``` ```python if "id" in data: entity_id = data["id"] elif "name" in data: entity_id = self._slugify(str(data["name"])) elif key: entity_id = key else: data_str = json.dumps(data, sort_keys=True) entity_hash = hashlib.md5(data_str.encode()).hexdigest()[:8] entity_id = entity_hash return f"{self.base_namespace}entity_{entity_id}" ``` ```python @staticmethod def _slugify(text: str) -> str: """Convert text to slug format.""" return text.lower().replace(" ", "_").replace("-", "_") ``` ### Technical Analysis The Turtle and N-Triples serializers directly interpolate attacker-controlled literal values into quoted RDF syntax. They do not escape quotation marks, backslashes, carriage returns, line feeds, control characters, or other syntax-significant characters. Entity identifiers read from JSON are also appended directly to the base namespace. The fallback `_slugify()` function only replaces spaces and hyphens and does not encode or reject characters such as `<`, `>`, `"`, `#`, backslashes, or control characters. Consequently, both RDF literal and IRI boundaries may b ...[truncated 1985 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The 'Literal Language Tagging' section hard-codes examples for English, French, and Spanish outputs and frames language tagging as a pattern to apply, but it does not mention preserving the user's original locale preferences or offering a language choice. This can be read as a locale-handling policy gap because language behavior is presented prescriptively without explicit user opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.