Back to skill

Security audit

Knowledge Graph - Tigergraph Connector

Security checks for vulnerabilities and agentic risk

Overview

This TigerGraph skill is coherent in purpose but needs review because it presents mock database operations as production-ready and gives agents broad database write/schema guidance without clear safeguards.

Review carefully before installing for any real TigerGraph environment. Treat the included Python connector as demo or scaffold code until real authentication, query execution, CSV parsing, error handling, and verification are implemented. Use least-privilege TigerGraph credentials, test graphs first, require explicit approval for inserts/schema/index changes, and pin dependencies in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:24
Finding

Unpinned and Unverified pyTigerGraph Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: README.md:24
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
pip install pyTigerGraph

Technical Analysis

The installation command retrieves the latest available pyTigerGraph release without enforcing an exact version, package hash, or trusted lock file. Consequently, the installed code can change over time without any corresponding change to this project.

The package name appears legitimate, and the audit found no evidence that the project currently retrieves a known malicious dependency. Nevertheless, this installation pattern leaves users exposed if the package registry, publisher account, release process, or dependency graph is compromised. Python packages may execute code during build or installation, and subsequently execute package-controlled code when imported.

Attack Path

  1. An attacker compromises the upstream package publisher, registry entry, release pipeline, or a transitive dependency.
  2. The attacker publishes a malicious release under the expected package name.
  3. A user follows the documented pip install pyTigerGraph command.
  4. pip resolves the unpinned dependency to the attacker-controlled release.
  5. Malicious code executes during package installation, wheel build, or later import by an application.
  6. The payload obtains the permissions of the user or service account running pip or the consuming application.

This path requires an external supply-chain compromise or malicious upstream release; no such compromise was confirmed during this audit.

Impact Assessment

Successful exploitation could permit arbitrary Python code execution with the privileges of the installing user. If installation is performed as root, within a privileged CI runner, or in a production service image, the impact may include host or build-environment compromise, theft of environment ...[truncated 353 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin pyTigerGraph to a reviewed, exact version, for example through a version-controlled requirements file.
  • Generate and verify cryptographic hashes using a tool such as pip-compile --generate-hashes, then install with pip install --require-hashes -r requirements.txt.
  • Prefer binary wheels where appropriate and disable unnecessary source builds in controlled deployment environments.
  • Use a trusted internal package mirror or allowlisted index for production and CI installations.
  • Scan direct and transitive dependencies with an automated vulnerability and provenance checking process.
  • Run package installation as an unprivileged user in an isolated virtual environment or build container.
  • Review and intentionally approve dependency upgrades rather than resolving the newest release during every installation.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:484
Finding

Unpinned and Unverified Python Dependencies in Skill Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:484
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
pip install pyTigerGraph requests

Technical Analysis

The skill instructions direct users or agents to install pyTigerGraph and requests without exact versions or cryptographic hashes. Dependency resolution therefore selects releases available at installation time rather than a set of artifacts reviewed with this project.

Both names correspond to established packages, and the audit found no evidence of typosquatting, a malicious package source, or an existing malicious payload. The weakness is the absence of reproducible and integrity-verified dependency resolution. A compromised publisher account, package registry, release artifact, or transitive dependency could turn the documented installation step into a code-execution channel.

Attack Path

  1. An attacker gains control of an upstream release channel or introduces a malicious transitive dependency.
  2. A malicious version becomes eligible for normal dependency resolution.
  3. A user or automated agent follows the skill instruction and runs the unpinned installation command.
  4. pip downloads the affected package and dependencies without comparing them against project-approved hashes.
  5. Attacker-controlled code runs during installation, build processing, or subsequent package import.
  6. The code accesses files, credentials, network resources, and services available to the installation or runtime account.

This exploitation path is conditional on an external supply-chain event. No direct remote-payload loader or embedded malicious code was found in the audited project.

Impact Assessment

Exploitation could result in arbitrary code execution under the installer or application account. Potential consequences include credential theft, CI/CD compromise, application artifact ...[truncated 325 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the inline installation command with a version-controlled, fully pinned dependency file.
  • Pin both direct and transitive packages to reviewed versions.
  • Include SHA-256 hashes for every permitted distribution and enforce them with --require-hashes.
  • Configure installations to use only approved package indexes; explicitly disable unintended extra indexes.
  • Perform dependency vulnerability, license, and provenance checks in CI.
  • Isolate installation and execution in a least-privileged virtual environment or container.
  • Establish a controlled dependency-update process that reviews release notes, artifact provenance, and security scan results before updating pins.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises data-loading capabilities such as vertex and edge insertion without clearly warning that these operations persistently modify graph contents. In an agent skill context, examples are often reused directly, so omission of safety guidance can cause unintended writes, corruption of production data, or accidental execution against the wrong graph.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Schema-management capabilities are documented without caution that schema changes can be destructive, affect availability, or invalidate existing queries and data-loading pipelines. In a database administration skill, this omission is dangerous because an agent may treat schema operations as routine and apply them to live systems without change-control awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The quick examples show insert_vertices and insert_edges calls with no notice that they write persistent data. Because README snippets are high-probability copy/paste material for users and autonomous agents, this increases the risk of accidental modification of production graphs or seeding test data into the wrong environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly advertises loading, managing, and modifying graph data but does not warn users that these operations can change persistent database state. In an agent setting, this increases the chance that a user or downstream automation invokes destructive or unintended write operations under the assumption that the skill is read-only or low-risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example triggers encourage actions like inserting vertices into TigerGraph without indicating that these commands will alter the target graph. In an autonomous or semi-autonomous agent workflow, such examples can normalize write operations and lead to unintended data modification, corruption, or policy violations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The connect() method reports a successful TigerGraph connection by only flipping local state flags and logging success, without authenticating to or contacting a TigerGraph server. This can cause downstream code to operate under a false trust boundary, leading users or higher-level agents to believe database operations succeeded when no real connectivity exists.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The run_query() method claims to execute GSQL queries but instead returns mocked results from _mock_query_execution(), while incrementing statistics as if a real query ran. In an agent skill context, this is dangerous because automation may make security-sensitive decisions based on fabricated database output, causing integrity failures and unsafe follow-on actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The load_from_csv() method logs that it is loading data from a CSV file but never reads the file and inserts an empty vertex list, yet still returns success. This creates silent failure and false assurances about data ingestion, which is especially risky in a data-management skill where agents may depend on the imported graph state for later decisions or analysis.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.