Back to skill

Security audit

Knowledge Graph - Text Entity Relation Extractor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward text extraction helper with a local rule-based example script and no evidence of hidden execution, exfiltration, persistence, or privilege escalation.

Install only if you want an agent to help extract entities and relationships from text. Avoid feeding it real medical, legal, financial, or confidential documents unless you are comfortable with the extracted graph outputs preserving sensitive details and you have appropriate privacy controls in place.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
70% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · examples/example-extractions.md (reported line 230)May include surrounding context.

text
Marie Curie was born in Warsaw, Poland in 1867. She moved to Paris, France 
to study physics at the University of Paris. There, she met Pierre Curie, 
a physicist and professor at the University. The couple married in 1895 
and began conducting groundbreaking research on radioactivity. Together, 
they discovered polonium and radium, winning the Nobel Prize in Physics 
in 1903. After Pierre's death in 1906, Marie continued her research and 
received the Nobel Prize in Chemistry in 1911, becoming the first person 
to win Nobel Prizes in two different fields.

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
70% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · examples/example-extractions.md (reported line 259)May include surrounding context.

md
- 1906
  - 1911

ENTITIES (PRODUCT/DISCOVERY):
  - Radioactivity
  - Polonium
  - Radium

RELATIONSHIPS:
  Marie Curie -[BORN_IN]-> Warsaw, Poland
  Marie Curie -[BORN_DATE]-> 1867

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
70% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · examples/example-extractions.md (reported line 271)May include surrounding context.

md
- 1906
  - 1911

ENTITIES (PRODUCT/DISCOVERY):
  - Radioactivity
  - Polonium
  - Radium

RELATIONSHIPS:
  Marie Curie -[BORN_IN]-> Warsaw, Poland
  Marie Curie -[BORN_DATE]-> 1867

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · references/extraction-patterns.md (reported line 163)May include surrounding context.

md
Approach:
  1. Identify entity pairs in sentence
  2. Extract context between entities
  3. Classify relationship type

Example:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly invites ingestion of unstructured documents, corpora, transcripts, and raw text, which commonly contain PII, confidential business data, or regulated content, yet it provides no privacy, retention, or redaction guidance. This can lead users to process sensitive data without minimization or safeguards, increasing the risk of data exposure through logs, downstream graph outputs, or external NLP libraries/services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The medical-report example contains realistic full names, age, dates, hospitals, procedures, and clinician identities, which models a sensitive health-data extraction workflow without any privacy warning, de-identification note, or guidance on handling PHI/PII. Even if illustrative, this can normalize processing or exposing medical records in ways that increase privacy and compliance risk for users of the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The 'Use When' section lists generic activities like 'Extracting entities from text' and 'Mining knowledge from documents' without defining specific trigger phrases, scope boundaries, or when the skill should not be used. For a markdown skill description, this makes activation intent overly broad and could increase unintended invocation in common text-processing contexts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.