Back to skill

Security audit

Knowledge Graph for Agents

Security checks for vulnerabilities and agentic risk

Overview

This skill is a transparent guide for adding knowledge-graph search, with privacy considerations around person and email extraction but no hidden execution or exfiltration behavior.

Before installing, make sure any graph built from emails, names, team data, or business documents is limited to data you are allowed to process, with retention, access controls, and redaction or opt-out choices where needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly recommends extracting entities from every indexed text chunk and includes email-address parsing that derives person identities, but it provides no warning, consent guidance, minimization strategy, or privacy controls for potentially sensitive data. In an agent memory or enterprise search context, this can normalize broad PII ingestion and relationship mapping, increasing privacy, compliance, and unintended exposure risks even if the underlying goal is functional rather than malicious.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.