Back to skill

Security audit

Knowledge Graph - Ontology Based Inference Helper

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local ontology-reasoning helper with some overstated or incorrect reasoning examples, but no evidence of hidden access, persistence, exfiltration, or destructive behavior.

Install only if you want conceptual ontology-inference guidance or a small demo engine. Do not rely on it as a complete RDF/OWL reasoner for production, compliance, medical, access-control, or policy decisions without fixing the documented reasoning gaps and validating outputs against a real reasoner.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill documentation advertises inference capabilities and strategies that are not actually implemented, creating a trust gap between expected and actual behavior. In security- or compliance-sensitive knowledge graph workflows, this can lead users to rely on missing validation and inference features, causing silent logic failures, incomplete reasoning, and incorrect policy or access decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The kinship example reverses the semantics of the inverse property: from 'A parent B' it incorrectly infers 'B hasChild A' instead of 'A hasChild B'. In an ontology inference helper, this kind of directional error can systematically generate false relationship data, corrupt downstream reasoning, and mislead any consumers relying on inferred family links.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring states this method performs 'Backward chaining: query-driven inference,' but the body just calls _forward_chaining() and changes the reported strategy string. This is an active contradiction between documentation and behavior, not merely an omitted detail.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill supports inferring new relationships, class memberships, properties, and domain/range constraints. However, domain/range inference is explicitly skipped in this implementation, property inheritance is a no-op, and the code has no mechanism to ingest explicit relationship facts from the knowledge graph, so most advertised inference behavior is not actually performed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The biomedical example uses 'rdf:type' where subclass relations should be expressed as 'subClassOf', conflating instance typing with class hierarchy semantics. In a reasoning skill focused on RDF/OWL inference, this can teach or reinforce incorrect modeling patterns, causing invalid inferences or broken interoperability with standards-compliant tooling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The location inference output includes 'Earth' even though that node is absent from the declared ontology. This demonstrates inference results that are not grounded in the provided schema, which can undermine trust in the skill and encourage consumers to accept hallucinated or out-of-ontology facts as valid conclusions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The method is documented as a 'Hybrid approach,' implying combined or distinct inference behavior. In reality it directly returns _forward_chaining(), so the documentation misrepresents what the code does.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.