Back to skill

Security audit

Knowledge Graph - Mapping Dsl Builder

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent mapping generator, but it ships code that can place unescaped user-provided values into executable mapping files, so real-data use deserves review.

Review and harden the builder before using it with untrusted schemas, column names, predicates, table names, URI templates, API endpoints, or credentials. Prefer the JSON/YAML structured paths with safe serializers, validate or escape all DSL/R2RML fields, and execute generated mappings only in least-privilege environments after checking for unintended sources or transformations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/dsl_builder.py:172
Finding

Unescaped Input Allows DSL and R2RML Mapping Injection

Content
View full analysis
str: """Generate custom DSL format.""" output = f"""mapping: {self.name} version: {self.version} description: {self.description or 'Auto-generated mapping'} source: type: {self.source.source_type.value if self.source else 'unknown'} location: {self.source.location if self.source else 'not defined'} """ if self.source.table_name: output += f" table: {self.source.table_name}\n" output += "\nentities:\n" for entity_id, entity in self.entities.items(): output += f""" - entity_id: {entity_id} type: {entity.entity_type} identifier: {entity.identifier_column} uri_template: "{entity.uri_template}" properties: """ for prop in entity.properties: output += f""" - source: {prop.source_column} predicate: {prop.target_predicate} type: {prop.datatype} """ ``` ```python def to_r2rml(self) -> str: """Generate R2RML Turtle format.""" output = """@prefix rr: . @prefix foaf: . @prefix schema: . @prefix ex: . @prefix xsd: . """ for entity_id, entity in self.entities.items(): entity_name = entity_id.replace("_", " ").title().replace(" ", "") output += f"ex:{entity_name}Mapping a rr:TriplesMap ;\n" if self.source and self.source.table_name: output += f' rr:logicalTable [ rr:tableName "{self.source.table_name}" ] ;\n' output += f""" rr:subjectMap [ rr:template "{entity.uri_template}" ; rr:class {entity.entity_type} ] ; """ for prop in entity.properties: o ...[truncated 4299 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file describes mapping workflows that include personal data such as email, birth date, salary, student records, and API review data, but it does not warn readers that these examples involve handling potentially sensitive information. Under the markdown-file criteria for SQP-2, the omission matters because the described behavior could affect user data and privacy.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/example-mappings.md (reported line 280)May include surrounding context.

md
source:
  type: json
  location: "file.json" OR "https://api.example.com/data"
  path: "$.data[*]"  # JSONPath
  format: "array" | "object" | "nested"
  authentication:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/mapping-patterns.md (reported line 54)May include surrounding context.

md
source:
  type: json
  location: "file.json" OR "https://api.example.com/data"
  path: "$.data[*]"  # JSONPath
  format: "array" | "object" | "nested"
  authentication:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/mapping-patterns.md (reported line 75)May include surrounding context.

md
source:
  type: json
  location: "file.json" OR "https://api.example.com/data"
  path: "$.data[*]"  # JSONPath
  format: "array" | "object" | "nested"
  authentication:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The pattern sets default: "en" for language tagging, which imposes a specific language/locale by default in natural-language content. SQP-3 applies because the file does not offer a user language choice or explain why English is the required default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown skill describes generating mappings from structured sources including databases and APIs, and later mentions executable mapping configurations, but it provides no user-facing warning about possible privacy or data-handling implications. For markdown files, SQP-2 applies when the description omits warnings about behaviors that could affect user data or privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes a JSON/API source pattern that supports HTTP APIs and authentication credentials, which could affect privacy or expose sensitive data if used, but the surrounding documentation provides no warning about network transmission or secret handling. Under the markdown-specific SQP-2 criteria, descriptions of behaviors affecting user data or privacy should disclose those risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The API source pattern documents connecting to a REST API with authorization headers and methods including POST, but it does not warn users that the pattern can transmit data to external services or involve sensitive tokens. For markdown files, SQP-2 applies when potentially privacy- or integrity-impacting behavior is described without a user-facing warning.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.