Back to skill

Security audit

Knowledge Graph - Neo4j Integration

Security checks for vulnerabilities and agentic risk

Overview

This Neo4j skill is not malicious, but it needs Review because it presents a simulated connector as production-ready real database software.

Review this skill carefully before installing. Treat scripts/neo4j_connector.py as a mock or demo, not a production Neo4j connector. Do not rely on its success status for real database writes, deletes, transactions, or audits. If using the Cypher examples against a live Neo4j instance, use least-privilege credentials, avoid hardcoded passwords, test on non-production data, confirm DELETE/DETACH DELETE targets, and limit any APOC export to approved data and paths.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/neo4j_connector.py:104
Finding

Database operations are silently simulated and falsely reported as successful

Content
View full analysis
bool: """Establish connection to Neo4j database.""" try: # Simulate Neo4j connection self.driver = { "uri": self.config.uri, "connected": True, "pool_size": self.config.pool_size } print(f"✓ Connected to Neo4j at {self.config.uri}") return True ``` ```python # Execute query (simulated) result = self._simulate_query_execution(query, parameters, query_type) return result ``` ```python def begin_transaction(self) -> bool: """Begin a transaction.""" self.transaction_status = TransactionStatus.ACTIVE print("✓ Transaction started") return True def commit_transaction(self) -> bool: """Commit the current transaction.""" if self.transaction_status == TransactionStatus.ACTIVE: self.transaction_status = TransactionStatus.COMMITTED print("✓ Transaction committed") return True return False def rollback_transaction(self) -> bool: """Rollback the current transaction.""" if self.transaction_status == TransactionStatus.ACTIVE: self.transaction_status = TransactionStatus.ROLLED_BACK print("✓ Transaction rolled back") return True return False ``` ```python def _simulate_query_execution( self, query: str, parameters: Optional[Dict[str, Any]], query_type: str ) -> QueryResult: """Simulate query execution.""" # Simulate result based on query type if query_type == "CREATE": return QueryResult( records=[{"created": True}], summary={"nodes_created": 1}, success=True, execution_time_ms=2.5 ) elif query_type == "READ": ...[truncated 2803 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/neo4j_connector.py:161
Finding

Unvalidated Cypher identifiers are interpolated into query strings

Content
View full analysis
(b) RETURN r """ ``` ```python if properties: where_clause = " AND ".join([f"n.{k} = ${k}" for k in properties.keys()]) query = f"MATCH (n:{label}) WHERE {where_clause} RETURN n" else: query = f"MATCH (n:{label}) RETURN n" ``` ```python query = f"CREATE INDEX idx_{label}_{property_name} FOR (n:{label}) ON (n.{property_name})" ``` ### Technical Analysis The `label`, `relationship_type`, property-key, index-name, and indexed-property inputs are inserted directly into Cypher through Python f-strings. Neo4j query parameters protect data values, but they do not automatically protect structural identifiers such as labels, relationship types, or property names. An attacker who can control any of these inputs may supply Cypher syntax rather than a valid identifier. If this query-building code is connected to a real Neo4j driver, malicious input could terminate or modify the intended query structure and introduce additional clauses. The current implementation simulates query execution, so the injection is latent in this version. It becomes directly exploitable if real execution is added while retaining the existing query construction. ### Attack Path 1. An application passes an attacker-controlled label, relationship type, property key, or index property to the connector. 2. The connector inserts the value directly into a Cypher statement without validation or safe identifier quoting. 3. The resulting statement contains attacker-controlled Cypher syntax. 4. A real Neo4j driver executes the altered statement using the c ...[truncated 1038 chars]
Remediation
View remediation
str: if not isinstance(value, str) or not IDENTIFIER.fullmatch(value): raise ValueError("Invalid Cypher identifier") return value ``` 3. Prefer explicit allowlists for labels, relationship types, indexed properties, and searchable property keys. 4. Apply validation independently to `label`, `relationship_type`, every property key, and `property_name`. 5. Safely quote identifiers according to Neo4j's identifier rules after validation where quoting is required. 6. Continue using Neo4j parameters for all data values. 7. Do not attempt to sanitize arbitrary Cypher using string replacement; reject invalid identifiers instead. 8. Run the connector under a least-privileged Neo4j account that cannot perform unnecessary schema or administrative operations. 9. Add negative tests containing spaces, backticks, parentheses, colons, clause keywords, and statement delimiters. 10. Review every future query-building method for structural interpolation before enabling real database execution. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description presents this as a functional Neo4j integration for real database storage/query/management. However, the code does not use a Neo4j driver, make network connections, authenticate, or execute Cypher against an actual database. connect() only stores a dictionary, and execute_query() routes to _simulate_query_execution() which returns canned results based on query type. Transaction methods only toggle an enum and print messages, without binding query execution to transactional semantics. The description also mentions bulk operations, but no bulk insert/update/query capability exists. While index creation and result-mapping concepts are partially represented, they are also simulated rather than backed by real Neo4j behavior. This is therefore a material description/behavior mismatch in primary capability, not just an implementation detail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown skill description includes a DELETE example that removes data, but it does not provide any warning about data loss, safe-use constraints, or the need to confirm destructive actions. For markdown files, safety-affecting behaviors that could impact user data should be accompanied by clear warnings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file includes a destructive DETACH DELETE example without any adjacent warning that it permanently removes nodes and all attached relationships. In an agent skill that helps users execute Neo4j queries, this increases the chance that a user or downstream agent copies the pattern into production and causes unintended data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The APOC export example shows full-database export to a file without warning that it can disclose sensitive graph data and create artifacts on disk. In the context of an integration skill intended to run database operations, this is materially risky because an agent may treat it as a normal pattern and export confidential data without user awareness or access-control review.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module and class docstrings explicitly represent this as a production Neo4j integration with real connection management, pooling, transactions, and query execution, but the code only simulates a driver and returns fabricated results. In an integration skill, this mismatch is security-relevant because downstream agents or operators may trust false success states, leading to skipped validation, incorrect security assumptions, and unsafe operational decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The final banner states the connector is 'ready for production use' even though all major database behaviors are mocked, including connection establishment and query execution. In this skill context, that message can cause users or automated systems to deploy or rely on a nonfunctional integration, masking failures and undermining monitoring, testing, and trust boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The README includes an example with inline credentials and demonstrates state-changing database operations like node and relationship creation without any warning about secret handling, least-privilege credentials, or the fact that these actions modify database state. In a skill intended to guide users in connecting to live Neo4j instances, this can normalize unsafe practices and increase the chance of accidental use of hardcoded credentials or unintended writes against production databases.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill asks for Neo4j connection credentials, including a password, but the markdown does not warn users to protect secrets or avoid exposing credentials in logs, shared prompts, or source files. Because this behavior affects privacy and system access, the description should include a brief handling warning.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.