T08 · Insecure Dependencies
- Location
SKILL.md:179- Finding
Automatic Installation and Execution of an Unpinned Third-Party Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but it asks for broad local indexing and optional external/persistent behaviors without enough guardrails.
Install only if you are comfortable with a skill that can scan and persist local folders, install and run an unpinned Python package, send graph data to optional external services, and run optional long-lived integrations. Avoid using it on secrets or highly sensitive corpora until install pinning, retention controls, URL restrictions, and explicit confirmations are added.
SKILL.md:179Automatic Installation and Execution of an Unpinned Third-Party Package
SKILL.md:827Unrestricted URL Fetching Enables Server-Side Request Forgery and Sensitive-Resource Ingestion
SKILL.md:640Python Code Injection and Credential Exposure Through Neo4j Parameter Interpolation
The activation condition is overly broad and can trigger on generic requests about files, code, or knowledge graphs, causing the skill to run in contexts where the user did not intend large-scale file processing. Because the skill can scan directories, persist outputs, invoke subagents, and perform optional networked actions, over-triggering materially increases the risk of unintended data access and disclosure.
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
- Never skip the corpus check warning.
- Always show token cost in the report.
- Never hide cohesion scores behind symbols - show the raw number.
- Never run HTML viz on a graph with more than 5,000 nodes without warning the user.
The skill persists derived knowledge bases under ~/.sdw/knowledge_bases/ and reuses them across sessions, which can retain sensitive information from scanned corpora beyond the immediate task. Persistent storage increases exposure if the source material contains secrets, proprietary code, internal documents, or personal data and users are not clearly warned about retention.
When the user invokes `/sdw-kb`, resolve the **working KB directory** (where `graphify-out/` lives and temp files are written) as follows:
1. **`/sdw-kb <path> --kb <name>`** — Use `<path>` as the input corpus. The KB directory is `~/.sdw/knowledge_bases/<name>/`. Create it if it doesn't exist.
2. **`/sdw-kb <path>`** (no `--kb`) — Use `<path>` as input. Derive the KB name from the last component of the path (e.g., `/home/user/projects/my-app` → KB name `my-app`). KB directory is `~/.sdw/knowledge_bases/my-app/`.
3. **`/sdw-kb --kb <name>`** (no path) — The KB must already exist at `~/.sdw/knowledge_bases/<name>/`. Use it for query/explain/path/cluster-only operations. If the KB doesn't exist, tell the user: "Knowledge base '<name>' not found. Run `/sdw-kb <source-path> --kb <name>` to create it."
4. **`/sdw-kb`** (no path, no --kb) — Use `.` (current directory) as input. Derive KB name from the current directory name.
The skill includes URL fetching and Neo4j push behaviors without clear user-facing warnings that content may be retrieved from or sent to external systems. In a security-sensitive environment, hidden or under-disclosed network transmission is dangerous because users may assume the tool only processes local data while it actually moves data across trust boundaries.
Starting an MCP server turns a batch graph-generation skill into a long-running service that exposes the generated knowledge base for external interaction. That increases attack surface, persistence, and potential unintended access to sensitive graph contents, especially if the server lifecycle and access controls are not clearly constrained.
Watch mode and repository/editor integrations exceed the stated one-shot graph-building purpose and introduce ongoing monitoring and system modification behavior. These features can continuously process new files or alter development tooling state, increasing persistence and the chance of unintended collection or execution in sensitive environments.
The skill's primary purpose is local graph construction, but it also supports fetching remote URLs and pushing graph data to Neo4j. Those capabilities create unannounced data egress and expand trust boundaries beyond the local machine, which can expose sensitive corpus contents or metadata if invoked without clear consent and safeguards.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Step 5 - Label communities
Read `.graphify_analysis.json`. For each community key, look at its node labels and write a 2-5 word plain-language name.
Then regenerate the report and save the labels:
The file explicitly states that all temp files should live in the KB directory and that later path references must be rewritten accordingly. But the transcription step uses graphify-out/.graphify_detect.json and writes graphify-out\.graphify_transcripts.json (L255-L261), contradicting the earlier instruction that temp files like .graphify_*.json belong at the KB root rather than under graphify-out/.
No suspicious patterns detected.