Back to skill

Security audit

Data Twingler Skill for SQL, SPARQL, and GraphQL

Security checks for vulnerabilities and agentic risk

Overview

This skill is for live database and knowledge-graph querying, but it gives agents broad network/query authority without enough endpoint, privacy, or input-safety boundaries.

Install only if you intend to let the agent contact live OpenLink and SPARQL/GraphQL services. Avoid using it with private prompts, internal endpoint URLs, proprietary graph names, or sensitive article titles unless you have added endpoint allowlists, literal/IRI escaping, read-only credentials, and explicit approval before any non-default or authenticated route.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/query-templates.md:53
Finding

Unrestricted User-Controlled Endpoint Access Enables SSRF

Content
View full analysis
{ SELECT ?s (COUNT(?s) AS ?count) ?o WHERE { GRAPH <{G}> { ?s a ?o . } } GROUP BY ?s ?o ORDER BY DESC(?count) LIMIT 50 } } ``` ``` The execution-routing instructions also explicitly prioritize direct requests: ```text Default execution order for query execution: 1. Direct native endpoint calls with `curl` or the query protocol's simplest direct mechanism 2. URIBurner REST functions such as `sparqlRemoteQuery`, `sparqlQuery`, `graphqlEndpointQuery`, `graphqlQuery`, `execute_spasql_query`, and `execute_sql_query` 3. MCP via `https://linkeddata.uriburner.com/chat/mcp/messages` or `https://linkeddata.uriburner.com/chat/mcp/sse` 4. Authenticated LLM-mediated execution via `https://linkeddata.uriburner.com/chat/functions/chatPromptComplete` 5. OPAL Agent routing using recognizable OPAL function names ``` ### Technical Analysis The `{E}` placeholder is derived from an endpoint URL supplied in the user's prompt and is inserted into a SPARQL `SERVICE` clause without an endpoint allowlist, URI-scheme restriction, DNS/IP validation, or redirect policy. The instructions also permit direct native requests using `curl`. Consequently, an attacker can cause either the local Agent environment or a remote SPARQL processor to initiate a connection to an attacker-selected destination. Depending on the selected route and network topology, targets could include loopback addresses, private-network services, link-local resou ...[truncated 1739 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/query-templates.md:80
Finding

Unsafe Placeholder Substitution Enables SPARQL Query Injection

Content
View full analysis
Remediation
View remediation
` or `GRAPH` syntax. 4. Reject malformed IRIs and values containing prohibited control characters or query delimiters. 5. Treat values obtained from RDF index queries as untrusted input even when they originate from a known graph. 6. Build `IN` filters from individually serialized literals rather than concatenating a comma-separated string. 7. Parse the final query into an abstract syntax tree and enforce an allowlisted structure before execution. 8. Reject unexpected `SERVICE`, update, subquery, dataset-selection, or vendor-extension constructs. 9. Display the finalized query and require approval when it accesses a new graph or uses federation. 10. Enforce server-side graph ACLs, read-only credentials, row limits, timeout limits, and query-complexity limits as defense in depth. 11. Add automated tests containing quotes, braces, backslashes, Unicode controls, comment markers, and attempted `SERVICE` injection in every placeholder. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises itself for very broad triggers such as generic questions like 'How to ...' and 'Define the term ...', which can cause the agent to invoke this networked skill in many ordinary conversations unrelated to databases or knowledge graphs. In this context, overbroad activation is dangerous because the skill is designed to contact live external endpoints and construct queries, increasing the risk of unnecessary data disclosure, unintended external requests, and context leakage from prompts that should have been handled locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description explicitly directs execution against live endpoints and external web services but provides no up-front notice that user queries, graph identifiers, or surrounding context may be transmitted off-platform. This is risky because users may unknowingly cause sensitive prompt content or proprietary context to be sent to third-party services during routine use of the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The execution routing instructs the agent to fall through to authenticated remote services, MCP endpoints, and LLM-mediated execution without any integrity, privacy, or trust boundary checks. This is particularly dangerous because it can escalate from direct querying to sending user content to additional remote processors, potentially with credentials, creating a larger attack surface for prompt/context exfiltration, unauthorized data transmission, and remote-side manipulation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file defines a trigger using an unconstrained placeholder for essentially any question, with only a vague context qualifier. Because it does not specify clear boundaries, examples, or exclusion conditions, the skill could match common everyday questions and invoke unintentionally.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 21)May include surrounding context.

text
and must not claim to be the original OpenLink Data Twingler configuration.

THIS SKILL CONFIGURATION IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
OPENLINK SOFTWARE BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY ARISING
FROM, OUT OF OR IN CONNECTION WITH THIS SKILL CONFIGURATION.

Static analysis

No suspicious patterns detected.