T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:29- Finding
Unrestricted Local File and Network Resource Access
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a real knowledge-graph generator, but it gives agents broad authority to fetch arbitrary local files and web URLs without clear safety limits.
Install only if you are comfortable with the agent reading user-supplied URLs and local file paths for graph generation. Use trusted public URLs or non-sensitive local files, avoid internal services and credential-bearing pages, and require confirmation before any file is fetched or saved.
SKILL.md:29Unrestricted Local File and Network Resource Access
prompts/generic-jsonld.md:41Indirect Prompt Injection Through Untrusted Source Content
The manifest states 'RDF-Turtle by default,' but later documentation says the Generic template for general web content produces JSON-LD and 'When uncertain, default to the Generic template,' which would not yield Turtle by default. These instructions create an active inconsistency about what default behavior the skill is supposed to implement.
The example trigger "Convert this page to structured semantic data" is comparatively generic and could match many unrelated transformation requests. The skill does not provide exclusion conditions or negative examples to narrow when this invocation should or should not occur.
The skill directs writing files to a fixed local directory without requiring user approval or warning that local state will be modified. In an agent environment, silent filesystem writes are dangerous because they can persist sensitive derived content, clutter host storage, or interact unexpectedly with other local processes and trust boundaries.
The instruction 'Language-tag the values of annotation attributes; apply properly according to JSON-LD syntax rules' imposes a locale-related requirement but does not specify that the language should be derived from source content or user preference. Because no opt-in or choice is provided, this creates a natural-language locale policy concern if the skill defaults or infers a language without user control.
The skill explicitly instructs saving generated artifacts to a fixed local directory, which expands behavior from content transformation into filesystem writes. Even though the path is not obviously sensitive, implicit local writes can surprise users, overwrite data if naming logic fails, and create a precedent for unauthorized persistence on the host.
The file says the template is for 'general web pages, articles, blog posts, and documentation' and instructs users to substitute placeholders before sending, but it does not define clear boundaries or exclusion conditions for when this prompt should or should not be used. In a markdown skill/prompt file, this can create ambiguity about activation scope and increase the chance of unintended use on unsuitable content types.
No suspicious patterns detected.