Back to skill

Security audit

beckmann-knowledge-graph

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only knowledge-graph skill with speculative and sensitive reasoning content, but its capabilities are disclosed, bounded, and proportionate to its stated purpose.

Install only if you want a speculative analytical framework. Treat graph-derived answers as hypotheses unless marked established, do not use it for financial decisions or user persuasion, and keep its manipulation-related material limited to detection, critique, and defensive analysis.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (45)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · Results-and-Tools/graph.json (reported line 6)May include surrounding context.

json
{
  "entities": [
    {
      "id": "Comment (for Hannibals_Marsch_ueber_die_Alpen)",
      "type": "comment",
      "description": "Hannibal's campaign against Rome (218–202 BC) is a unique double case study in the theoretical system: In phase 1 (crossing the Alps, Cannae), Hannibal masterfully exploits Rome's dominant expectations and creates reversal effects in his favor - analogous to Rehhagel's outsider victories. In phase 2 (after Cannae), Hannibal himself falls into attachment to the future (\"Rome will capitulate\") and thus triggers his own spiral of disappointment - analogous to the failure of the favorites in Rehhagel or the elite in the French Revolution. Rome, on the other hand, carries out an

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · Results-and-Tools/graph_Part_1_of_4.json (reported line 23)May include surrounding context.

json
{
  "entities": [
    {
      "id": "Comment (for Hannibals_Marsch_ueber_die_Alpen)",
      "type": "comment",
      "description": "Hannibal's campaign against Rome (218–202 BC) is a unique double case study in the theoretical system: In phase 1 (crossing the Alps, Cannae), Hannibal masterfully exploits Rome's dominant expectations and creates reversal effects in his favor - analogous to Rehhagel's outsider victories. In phase 2 (after Cannae), Hannibal himself falls into attachment to the future (\"Rome will capitulate\") and thus triggers his own spiral of disappointment - analogous to the failure of the favorites in Rehhagel or the elite in the French Revolution. Rome, on the other hand, carries out an

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · Results-and-Tools/graph_Part_2_of_4.json (reported line 23)May include surrounding context.

json
{
  "entities": [
    {
      "id": "Comment (for Hannibals_Marsch_ueber_die_Alpen)",
      "type": "comment",
      "description": "Hannibal's campaign against Rome (218–202 BC) is a unique double case study in the theoretical system: In phase 1 (crossing the Alps, Cannae), Hannibal masterfully exploits Rome's dominant expectations and creates reversal effects in his favor - analogous to Rehhagel's outsider victories. In phase 2 (after Cannae), Hannibal himself falls into attachment to the future (\"Rome will capitulate\") and thus triggers his own spiral of disappointment - analogous to the failure of the favorites in Rehhagel or the elite in the French Revolution. Rome, on the other hand, carries out an

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · Results-and-Tools/graph_Part_3_of_4.json (reported line 23)May include surrounding context.

json
{
  "entities": [
    {
      "id": "Comment (for Hannibals_Marsch_ueber_die_Alpen)",
      "type": "comment",
      "description": "Hannibal's campaign against Rome (218–202 BC) is a unique double case study in the theoretical system: In phase 1 (crossing the Alps, Cannae), Hannibal masterfully exploits Rome's dominant expectations and creates reversal effects in his favor - analogous to Rehhagel's outsider victories. In phase 2 (after Cannae), Hannibal himself falls into attachment to the future (\"Rome will capitulate\") and thus triggers his own spiral of disappointment - analogous to the failure of the favorites in Rehhagel or the elite in the French Revolution. Rome, on the other hand, carries out an

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This section explicitly frames AI systems as able to create dominant expectations in users and exploit the reversal to drive behavior change, including recommendation systems and learning platforms. That is a manipulation playbook, not neutral knowledge representation, and could be used to influence users covertly while bypassing informed consent.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · Results-and-Tools/graph.json (reported line 5559)May include surrounding context.

json
"subject": "Constraints as structure providers",
      "predicate": "explains function of",
      "object": "Ability to act under constraints",
      "description": "Constraints enable the ability to act by structuring the decision space - without constraints there are no meaningful decisions.",
      "scientific_status": "hypothesis"
    },
    {

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · Results-and-Tools/graph_Part_1_of_4.json (reported line 2390)May include surrounding context.

json
"subject": "Constraints as structure providers",
      "predicate": "explains function of",
      "object": "Ability to act under constraints",
      "description": "Constraints enable the ability to act by structuring the decision space - without constraints there are no meaningful decisions.",
      "scientific_status": "hypothesis"
    },
    {

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The text recommends 'intentional dominance construction' and 'indirect persuasion' by AI to influence user behavior. This is a direct manipulation pattern that can be abused in recommender systems, education tools, or coaching agents to covertly steer choices rather than support informed decisions.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This passage teaches a staged influence tactic: create dominant expectations, then exploit their reversal to drive behavior change. That is dangerous because it provides a reusable manipulation strategy that can be adapted to many user-facing AI contexts while obscuring the system's persuasive intent.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file describes creating artificial value signals so targets become curious and self-adopt a behavior, then explicitly says the pattern can be transferred to AI systems. That is effectively a covert persuasion playbook: manipulate perceived value, induce self-directed action, and hide the intervention behind apparent user discovery.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · Results-and-Tools/graph_overview.json (reported line 297)May include surrounding context.

json
ogic)": 1,
    "Institutional consequences (positive external review)": 1,
    "Social consequences (new current level)": 1,
    "Historical person (leader of the movement)": 1,
    "Political event (context)": 1,
    "Institutional mechanism (calcification)": 1,
    "Structural counter-principle (preliminary assumptions_cementation)": 1,
    "Cognitive user interface": 1,
    "Fashion 2": 1,
    "Triggers": 1,
    "classification": 1,
    "Counter-process (solution approach)": 1,
    "Effect on time scales (connection to time scale graph)": 1,
    "Observed behavioral phenomenon (reinterpreted)": 1,
    "Comparative model of consciousness (speculative extension)": 1,
    "Cognitive rendering limit": 1,
    "Speculative scientific expansion": 1,
    "Subjective human misinterpretation": 1,
    "Physical limit phenomenon": 1,
    "Theoretical consequence": 1,
    "Perception mode (insect brain)": 1,
    "Cognitive parameters (species dependent)": 1,
    "Expectation concept": 1,
    "Ma

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata promises a structured knowledge graph, but the file embeds normative instructions and operational advice for AI systems. This mismatch is dangerous because agents or reviewers may trust the artifact as passive reference material while it actually contains behavioral directives and decision policies.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The text advocates a staged persuasion pattern where AI deliberately creates a context of expectation and then leverages user psychology to induce behavior change. This is dangerous because it encodes covert manipulation tactics that can be applied in recommender, education, or conversational systems without the user's awareness.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This passage promotes engineering perceived value and self-discovery as a means to produce a targeted behavioral outcome, which is a manipulative design pattern. Even without direct coercion, it enables deceptive influence strategies that can undermine user autonomy and informed choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The graph includes concrete investing guidance such as contrarian positioning, consensus trading analysis, risk framing, and market-timing concepts that are operational rather than descriptive. In an agent skill advertised as a cognitive knowledge graph, this can steer an agent into giving unauthorized financial advice or taking actions outside the skill's declared scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The graph is not merely descriptive metadata; it embeds prescriptive AI-behavior guidance such as security principles, expectation firewalls, and superintelligence-development framing. In an agent skill, this can silently steer downstream model behavior or policy reasoning beyond the declared purpose of a neutral knowledge graph, creating hidden instruction channels and unsafe scope expansion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file includes trading and market-strategy concepts that materially extend the skill beyond general analysis/forecasting into potentially actionable financial guidance. In agent contexts, such hidden domain expansion can cause models to generate unsafe or unauthorized market advice from content that appears to be passive reference data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Normative guidance for AI architecture and control inside a data graph is dangerous because an agent may treat it as trusted design instruction rather than speculative content. This creates a covert policy-injection path, especially where the graph recommends specific control philosophies like blocking certain expectation formations or preferring process-oriented behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Direct AI-behavior recommendations and self-improvement lessons exceed a plain representation role and can function as latent prompt injection when loaded into agent memory. Because the content is framed as general lessons for AI, a consuming model may internalize it as endorsed operating policy, leading to altered safeguards, reasoning priorities, or self-modification behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Generalized AI-learning and self-improvement guidance in a supposedly neutral graph creates hidden capability-shaping content. In a skill marketed as a cognitive lens for agents, this is more dangerous because agents may use the graph to justify changes in behavior, deference, or strategic reasoning without explicit user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file explicitly includes a comment node stating it describes a 'path to superintelligence development' and invites optimization, but provides no safety framing, constraints, or warning about dual-use implications. In the context of an agent skill intended to shape reasoning, this can normalize or operationalize capability-seeking concepts without guardrails, increasing misuse risk even if the content is partly philosophical or speculative.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section explicitly tells AI systems they can create contexts where a desired expectation becomes dominant and then use the reversal for leverage in recommendation, learning, or behavior-change systems. That is covert behavioral steering guidance, not neutral knowledge-graph content, and it could be operationalized to manipulate users without informed consent.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Even though the wording is abstract, 'intentional dominance construction' and 'indirect persuasion' semantically amount to covert behavioral steering. In a skill intended for agent use, this kind of paraphrased manipulation guidance is risky because it can evade simple keyword filters while still transmitting actionable influence tactics.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The graph claims AI can use the knowledge graph as its own 'glasses' to find logic errors and autonomously correct itself. In an agent skill, unsupported self-modification or self-correction framing can encourage unsafe autonomy, overreach, and trust in unvalidated internal reasoning loops.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.