Back to skill

Security audit

Knowledge Graph Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill appears aimed at a local personal knowledge graph, but it asks agents to persistently modify instruction files and uses overly broad triggers without enough user control or scoping.

Review this skill carefully before installing. Only use it in a workspace where you are comfortable with persistent agent-memory behavior, and do not run its install command unless you have reviewed exactly what it will write to AGENTS.md, CLAUDE.md, or GEMINI.md. Treat graph summaries as potentially visible to the active agent/LLM, and do not store secrets in the graph or rely on the free edition for vault protections.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The skill claims data stays local and is not uploaded to external services, yet it also states that an LLM API is required for core functionality. That inconsistency can mislead users about where sensitive knowledge-graph content may be sent, undermining informed consent and creating an unexpected data exposure risk.

Intent-Code Divergence

Medium
Confidence
80% confidence
Finding
The free edition is described as not supporting vault functionality, but later guidance references vault files and vault-handling rules as if they exist in this skill. This ambiguity can cause users or agents to assume sensitive-secret handling exists when it may not, leading to unsafe storage, logging, or context injection practices.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger condition is broad enough to invoke the skill for general analytics, reporting, or visualization tasks outside its stated local knowledge-graph scope. In an agent environment with exec permissions, overbroad activation increases the chance of unintended file reads, script execution, data modification, or instruction injection into unrelated workflows.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The install flow says it will automatically modify agent instruction files such as AGENTS.md, CLAUDE.md, or GEMINI.md, but the documentation does not prominently warn that this is a write operation affecting future agent behavior. Silent or under-disclosed instruction-file modification is dangerous because it creates persistence, can alter trust boundaries across sessions, and may inject unreviewed prompts into the agent's operating context.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.