graph-query
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands using the
graphifyCLI, where user input is directly interpolated into the command string (e.g.,graphify query "<question>"). This creates a surface for command injection if the user input is not properly sanitized or escaped before execution. - [INDIRECT_PROMPT_INJECTION]: The skill processes content from
graphify-out/graph.json, which is derived from external codebase and wiki files, creating a vulnerability to instructions embedded in processed data. - Ingestion points: The agent is instructed to read and process the
graphify-out/graph.jsonfile inSKILL.md. - Boundary markers: The instructions lack specific delimiters or warnings to ignore potentially malicious instructions embedded within the graph data.
- Capability inventory: The skill possesses file read capabilities and the ability to execute CLI tools (
graphify). - Sanitization: There is no mention of sanitizing or validating the content retrieved from the graph before it is processed by the agent.
Audit Metadata