Back to skill

Security audit

Knowledge Graph Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real knowledge-graph generator, but it gives agents broad authority to fetch arbitrary local files and web URLs without clear safety limits.

Install only if you are comfortable with the agent reading user-supplied URLs and local file paths for graph generation. Use trusted public URLs or non-sensitive local files, avoid internal services and credential-bearing pages, and require confirmation before any file is fetched or saved.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:29
Finding

Unrestricted Local File and Network Resource Access

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
prompts/generic-jsonld.md:41
Finding

Indirect Prompt Injection Through Untrusted Source Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest states 'RDF-Turtle by default,' but later documentation says the Generic template for general web content produces JSON-LD and 'When uncertain, default to the Generic template,' which would not yield Turtle by default. These instructions create an active inconsistency about what default behavior the skill is supposed to implement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The example trigger "Convert this page to structured semantic data" is comparatively generic and could match many unrelated transformation requests. The skill does not provide exclusion conditions or negative examples to narrow when this invocation should or should not occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs writing files to a fixed local directory without requiring user approval or warning that local state will be modified. In an agent environment, silent filesystem writes are dangerous because they can persist sensitive derived content, clutter host storage, or interact unexpectedly with other local processes and trust boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instruction 'Language-tag the values of annotation attributes; apply properly according to JSON-LD syntax rules' imposes a locale-related requirement but does not specify that the language should be derived from source content or user preference. Because no opt-in or choice is provided, this creates a natural-language locale policy concern if the skill defaults or infers a language without user control.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs saving generated artifacts to a fixed local directory, which expands behavior from content transformation into filesystem writes. Even though the path is not obviously sensitive, implicit local writes can surprise users, overwrite data if naming logic fails, and create a precedent for unauthorized persistence on the host.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file says the template is for 'general web pages, articles, blog posts, and documentation' and instructs users to substitute placeholders before sending, but it does not define clear boundaries or exclusion conditions for when this prompt should or should not be used. In a markdown skill/prompt file, this can create ambiguity about activation scope and increase the chance of unintended use on unsuitable content types.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.