Back to skill

Security audit

Knowledge Graph - Rdf Triple Store Integration

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it needs review because it can guide agents to modify or delete RDF store data and query external endpoints without enough guardrails.

Review this skill before installing in a workspace connected to real RDF stores. Use read-only credentials by default, require explicit confirmation for INSERT/DELETE/DROP/UPDATE operations, test against non-production graphs first, avoid copying f-string SPARQL construction with untrusted input, and only allow federated SERVICE calls to approved endpoints with non-sensitive data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:604
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md:600-605
  • README.md:20-25

Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:600-605:

markdown
### Installation

```bash
pip install rdflib sparqlwrapper requests pydantic
text

`README.md:20-25`:

```markdown
### Installation

```bash
pip install rdflib sparqlwrapper
text

### Technical Analysis

The installation instructions request packages by name without specifying reviewed versions, cryptographic hashes, a lockfile, or an explicitly trusted package index. Consequently, package resolution depends on the mutable state of the configured Python package repositories at installation time.

Installing a Python package may execute build backends, setup hooks, or package code with the privileges of the user running `pip`. If an upstream dependency is compromised, a malicious release is published, or package-index configuration redirects resolution to an untrusted source, following these instructions can install and execute attacker-controlled code.

The `requests` and `pydantic` packages are documented as installation requirements in `SKILL.md`, but the audited connector does not import them. Unnecessary dependencies enlarge the supply-chain attack surface without providing functionality in the current implementation.

### Attack Path

1. An attacker compromises a listed package, its maintainer account, or a package repository used by the victim.
2. The attacker publishes a malicious release that satisfies the unconstrained package name.
3. A user follows the documented `pip install` command.
4. `pip` resolves the malicious or compromised release because no approved version or hash is enforced.
5. Malicious installation or runtime code executes under the installing user's account.
6. Depending on that account's permissions, the payload can access project files, u
...[truncated 826 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed version, for example:

    text
    rdflib==<reviewed-version>
    SPARQLWrapper==<reviewed-version>
    
  2. Generate a lockfile or requirements file containing cryptographic hashes, and install with hash verification:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Remove requests and pydantic from the installation instructions unless the implementation actually requires them.

  4. Use an explicitly trusted package index or an internally controlled package mirror rather than relying on ambient pip configuration.

  5. Review transitive dependencies and automate vulnerability scanning with tools such as pip-audit in CI.

  6. Perform installations in an isolated virtual environment or container under a non-privileged account. Do not install dependencies with administrator or root privileges.

  7. Keep the commands in README.md and SKILL.md synchronized with the reviewed lockfile so users do not bypass the pinned dependency set.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file explicitly advertises insert, update, delete, and graph management operations, but it does not include any caution that these actions can modify or remove RDF data. Under the markdown-specific warning criteria, skills that may affect user data or system integrity should disclose those risks clearly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README includes concrete examples for inserting a triple and updating data, both of which change persisted RDF content, yet the surrounding documentation provides no warning about irreversible or unintended data changes. For markdown skill descriptions, omission of such warnings is a safety disclosure gap.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly advertises SPARQL update, insert, and delete capabilities but does not prominently warn that these operations can permanently modify or remove data. In an agent context, that omission is dangerous because users may invoke the skill for querying while the model is also empowered to perform destructive updates, increasing the risk of accidental or unauthorized data loss.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples present dynamically constructed SPARQL queries using f-strings with caller-controlled values such as city names, department names, and URIs. In an RDF/SPARQL integration skill, readers are likely to copy these patterns into production code, enabling SPARQL injection, query manipulation, unexpected data exposure, or expensive queries against local or remote endpoints; the 'best practices' claim makes this more dangerous by lending unsafe code undue credibility.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file presents INSERT, DELETE, and graph-wide modification patterns as normal usage examples without any caution about irreversible or broad data changes. In practice, users may run these examples against production stores and unintentionally alter or remove triples, graphs, or entire resource descriptions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation includes SPARQL SERVICE examples that contact external endpoints such as DBpedia and other remote services. In a triple-store integration skill, this materially expands capability from local RDF query execution to outbound network access, which can leak query contents, identifiers, and linked data context to third parties if users copy these patterns without understanding the trust boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The federated query examples use SERVICE without warning that remote endpoints receive query fragments and possibly locally bound identifiers, which can expose sensitive graph relationships or investigative context. Because these are framed as reusable patterns, readers may adopt them without recognizing the data disclosure and dependency risks of external SPARQL services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The examples explicitly use federated queries and DBpedia SERVICE calls to a public external SPARQL endpoint, but the documentation does not warn users that running these examples transmits query data over the network to a third party. In this skill context, external querying is expected functionality, so the issue is not the feature itself but the lack of disclosure, which can lead to unintentional data sharing, privacy issues, or policy violations if users adapt the pattern with sensitive data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.