Back to skill

Security audit

Knowledge Graph Builder Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a local knowledge-graph helper that openly writes graph data files in the workspace and does not show hidden network, credential, or destructive behavior.

Before installing, understand that using the skill may create or append files under memory/knowledge-graph in your workspace. Review existing graph files before running append commands, and avoid storing real passwords, tokens, or secrets in graph entries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to create and append to local files under memory/knowledge-graph using shell commands, but it does not provide a prominent upfront warning that these operations mutate persistent local state. In an agent environment with exec enabled, this can lead to unintended file creation or modification, surprising users and potentially polluting or overwriting workspace data if invoked without explicit confirmation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.