graph-query

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands using the graphify CLI, where user input is directly interpolated into the command string (e.g., graphify query "<question>"). This creates a surface for command injection if the user input is not properly sanitized or escaped before execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from graphify-out/graph.json, which is derived from external codebase and wiki files, creating a vulnerability to instructions embedded in processed data.
  • Ingestion points: The agent is instructed to read and process the graphify-out/graph.json file in SKILL.md.
  • Boundary markers: The instructions lack specific delimiters or warnings to ignore potentially malicious instructions embedded within the graph data.
  • Capability inventory: The skill possesses file read capabilities and the ability to execute CLI tools (graphify).
  • Sanitization: There is no mention of sanitizing or validating the content retrieved from the graph before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 07:20 PM
Security Audit — agent-trust-hub — graph-query