Back to skill

Security audit

Sdw Kb

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it asks for broad local indexing and optional external/persistent behaviors without enough guardrails.

Install only if you are comfortable with a skill that can scan and persist local folders, install and run an unpinned Python package, send graph data to optional external services, and run optional long-lived integrations. Avoid using it on secrets or highly sensitive corpora until install pinning, retention controls, URL restrictions, and explicit confirmations are added.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:179
Finding

Automatic Installation and Execution of an Unpinned Third-Party Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:827
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery and Sensitive-Resource Ingestion

Content
View full analysis
` is given, use that KB. Otherwise derive from the current directory name. The graph file is at `$KB_DIR/graphify-out/graph.json`. All `python -c` commands use `& $UV_PYTHON -c` where `$UV_PYTHON = "$(uv tool dir)/graphifyy/Scripts/python"`. For **query**: BFS (default) or DFS (`--dfs`) traversal on `$KB_DIR/graphify-out/graph.json`. For **path**: shortest path between two concepts. For **explain**: plain-language explanation of a single node and its connections. For **add**: fetch URL, save to `$KB_DIR/raw/`, then auto-run `--update`. ``` ### Technical Analysis The `add` operation accepts a URL, fetches its response, saves it under the persistent knowledge-base directory, and automatically processes it. The instructions define no security controls for the destination or returned content. Missing controls include: - An allowed-protocol list. - Rejection of loopback, link-local, private, multicast, and reserved addresses. - DNS rebinding defenses. - Validation of every redirect target. - Explicit blocking of cloud metadata endpoints. - Response-size, decompression, timeout, and redirect limits. - User confirmation before fetching or persisting remote content. If the underlying fetching implementation supports additional URL schemes, local files or non-HTTP resources may also be reachable. Even when only HTTP and HTTPS are supported, unrestricted access can target internal services unavailable to an external attacker. The subsequent automatic `--update` operation increases exposure by parsing and persisting fetched data in graph artifacts. ### Attack Path 1. An attacker persuades a user or Agent ...[truncated 1221 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:640
Finding

Python Code Injection and Credential Exposure Through Neo4j Parameter Interpolation

Content
View full analysis
`**: ```powershell $UV_PYTHON = "$(uv tool dir)/graphifyy/Scripts/python" & $UV_PYTHON -c " import sys, json from graphify.build import build_from_json from graphify.cluster import cluster from graphify.export import push_to_neo4j from pathlib import Path extraction = json.loads(Path('.graphify_extract.json').read_text()) analysis = json.loads(Path('.graphify_analysis.json').read_text()) G = build_from_json(extraction) communities = {int(k): v for k, v in analysis['communities'].items()} result = push_to_neo4j(G, uri='NEO4J_URI', user='NEO4J_USER', password='NEO4J_PASSWORD', communities=communities) print(f'Pushed to Neo4j: {result[\"nodes\"]} nodes, {result[\"edges\"]} edges') " ``` ``` ### Technical Analysis The instructions place the Neo4j URI, username, and password directly inside a Python program passed to `python -c`. If placeholders are replaced through textual substitution, values containing a single quote, backslash, newline, or Python syntax can break out of the intended string literal. For example, a malicious value can close the `uri` string, insert a Python expression or command-execution statement, and comment out the remainder. The shell then launches Python, which parses the injected text as executable source. Even without malicious input, embedding the password in a command-line argument can expose it through process inspection, command logging, terminal transcripts, diagnostic output, or shell history. ### Attack Path 1. An attacker controls or influences a Neo4j URI, username, or password supplied to the Skill. 2. The value contains a quote followed by Python code designed to execute an operating-system command. 3. The Agent replaces `NEO4J_URI`, `NEO4J_USER`, or `NEO4J_PASSWORD` direc ...[truncated 1041 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The activation condition is overly broad and can trigger on generic requests about files, code, or knowledge graphs, causing the skill to run in contexts where the user did not intend large-scale file processing. Because the skill can scan directories, persist outputs, invoke subagents, and perform optional networked actions, over-triggering materially increases the risk of unintended data access and disclosure.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 873)May include surrounding context.

md
- Never skip the corpus check warning.
- Always show token cost in the report.
- Never hide cohesion scores behind symbols - show the raw number.
- Never run HTML viz on a graph with more than 5,000 nodes without warning the user.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The skill persists derived knowledge bases under ~/.sdw/knowledge_bases/ and reuses them across sessions, which can retain sensitive information from scanned corpora beyond the immediate task. Persistent storage increases exposure if the source material contains secrets, proprietary code, internal documents, or personal data and users are not clearly warned about retention.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
When the user invokes `/sdw-kb`, resolve the **working KB directory** (where `graphify-out/` lives and temp files are written) as follows:

1. **`/sdw-kb <path> --kb <name>`** — Use `<path>` as the input corpus. The KB directory is `~/.sdw/knowledge_bases/<name>/`. Create it if it doesn't exist.
2. **`/sdw-kb <path>`** (no `--kb`) — Use `<path>` as input. Derive the KB name from the last component of the path (e.g., `/home/user/projects/my-app` → KB name `my-app`). KB directory is `~/.sdw/knowledge_bases/my-app/`.
3. **`/sdw-kb --kb <name>`** (no path) — The KB must already exist at `~/.sdw/knowledge_bases/<name>/`. Use it for query/explain/path/cluster-only operations. If the KB doesn't exist, tell the user: "Knowledge base '<name>' not found. Run `/sdw-kb <source-path> --kb <name>` to create it."
4. **`/sdw-kb`** (no path, no --kb) — Use `.` (current directory) as input. Derive KB name from the current directory name.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill includes URL fetching and Neo4j push behaviors without clear user-facing warnings that content may be retrieved from or sent to external systems. In a security-sensitive environment, hidden or under-disclosed network transmission is dangerous because users may assume the tool only processes local data while it actually moves data across trust boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Starting an MCP server turns a batch graph-generation skill into a long-running service that exposes the generated knowledge base for external interaction. That increases attack surface, persistence, and potential unintended access to sensitive graph contents, especially if the server lifecycle and access controls are not clearly constrained.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Watch mode and repository/editor integrations exceed the stated one-shot graph-building purpose and introduce ongoing monitoring and system modification behavior. These features can continuously process new files or alter development tooling state, increasing persistence and the chance of unintended collection or execution in sensitive environments.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill's primary purpose is local graph construction, but it also supports fetching remote URLs and pushing graph data to Neo4j. Those capabilities create unannounced data egress and expand trust boundaries beyond the local machine, which can expose sensitive corpus contents or metadata if invoked without clear consent and safeguards.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 527)May include surrounding context.

md
### Step 5 - Label communities

Read `.graphify_analysis.json`. For each community key, look at its node labels and write a 2-5 word plain-language name.

Then regenerate the report and save the labels:

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file explicitly states that all temp files should live in the KB directory and that later path references must be rewritten accordingly. But the transcription step uses graphify-out/.graphify_detect.json and writes graphify-out\.graphify_transcripts.json (L255-L261), contradicting the earlier instruction that temp files like .graphify_*.json belong at the KB root rather than under graphify-out/.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.