Back to skill

Security audit

Knowledge Graph - Schema Migration Diff

Security checks for vulnerabilities and agentic risk

Overview

This skill is a schema-migration helper with some imperfect and potentially risky examples, but it does not show hidden behavior, credential access, persistence, or automatic destructive actions.

Install only if you want lightweight schema-diff guidance and example migration patterns. Treat generated or copied migration commands as drafts: test on staging, back up data, verify counts and relationships, and avoid running REMOVE, DELETE, or DROP steps against production without explicit review and rollback planning.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The implemented behavior partially matches the declared description: it does analyze schema differences across versions for entities, properties, and relationships, and provides a basic risk assessment. However, a substantial part of the declared purpose is missing. There is no functionality for producing migration plans, no generation of executable migration scripts, and no advanced handling for safe schema evolution beyond simple high/low risk labels. No undeclared sensitive capabilities or resource access are present, but the declared description overstates the code's actual functionality in a material way.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The migration examples include destructive operations such as removing properties and creating relationships without an explicit warning that these changes can alter or damage production data if applied blindly. In a schema-migration skill, users may copy scripts directly, so omission of prominent safety guidance increases the risk of unintended data loss, integrity issues, or unsafe execution in live environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example migration includes a destructive step that removes the old property (REMOVE s.name) after copying data to a new field, but the surrounding example does not explicitly warn that this is irreversible without backup or rollback planning. In a skill focused on generating migration plans and scripts, users may treat examples as safe templates and execute them in production, increasing the risk of unintended data loss if the rename was incomplete, validation was skipped, or downstream systems still depend on the old field.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide presents destructive operations such as removing old properties immediately after copying data, but it does not place an explicit warning adjacent to the commands about backups, transaction scope, rollback readiness, and verification requirements. In a schema-migration skill, users may copy these commands directly into production, increasing the risk of irreversible data loss or premature deletion if the migration was incomplete or incorrect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The rollback examples include deleting relationships and dropping constraints without an immediate warning that these actions can remove valid data or weaken integrity guarantees if applied broadly or to the wrong environment. Although rollback is a legitimate topic for this skill, presenting destructive rollback commands without scoped safeguards or cautionary context makes operator error more likely.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description claims broader functionality than is implemented: safe schema evolution planning and script generation. In this file, the implemented behavior is limited to collecting schema elements, computing added/removed differences, and printing a textual report with a simple risk summary.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The 'Use When' section lists broad scenarios such as 'Planning schema evolution' and 'Refactoring graph models' without defining specific trigger phrases, scope boundaries, or exclusion conditions. In a markdown skill description, this can make it unclear when the skill should activate versus when a more general graph-design or migration tool should be used.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The section is labeled as a validation check, but the Cypher example defines before_count in one query fragment and later compares after_count = before_count after a separate MATCH, where before_count is no longer in scope. This documentation claims to demonstrate a working safety validation pattern, but the shown code would not actually perform the stated comparison as written.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The documentation and type definitions imply broader change-analysis intent than the operational code delivers. Although MODIFIED and RENAMED are defined in the enums and repr, compute_diff only detects added and removed entities, properties, and relationships, so the documented/declared intent is only partially implemented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.