graph
Fail
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the installation of a package named 'graphifyy' using pip, uv, or pipx (e.g.,
pip install graphifyy). Throughout the rest of the file, the tool is referred to as 'graphify'. This naming discrepancy is a common indicator of typosquatting, where malicious actors publish packages with names similar to popular libraries to achieve remote code execution on the user's machine.\n- [COMMAND_EXECUTION]: The skill requires the execution of a local Python scripttools/graphify_setup.py. This allows the skill to execute arbitrary code within the user's environment before the primary tool is even run.\n- [PERSISTENCE]: The skill encourages the installation of a git hook viagraphify hook install. Git hooks are scripts that run automatically during common developer actions like commits, allowing the tool to maintain persistence and execute its code repeatedly without explicit user interaction.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze the repository's source code and markdown documentation to build a knowledge graph, creating a significant attack surface for indirect prompt injection.\n - Ingestion points: The process reads all source code files and markdown files within the
wiki/directory.\n - Boundary markers: There are no defined delimiters or specific instructions for the agent to treat ingested data as untrusted or to ignore instructions embedded within those files.\n
- Capability inventory: The skill environment allows for package installation, local script execution, and file system modifications.\n
- Sanitization: The skill lacks any mentioned sanitization or filtering logic for the content it ingests, which could allow malicious instructions in the code or wiki to influence the agent's behavior.
Recommendations
- AI detected serious security threats
Audit Metadata