graphify-windows

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior mostly matches the stated purpose of building and querying knowledge graphs, and the install path appears to use the official PyPI package. However, the skill has a broad footprint: arbitrary folder ingestion, arbitrary URL fetching, parallel subagent analysis of untrusted content, optional persistent hooks/watchers, and optional outbound Neo4j export. The main concern is not obvious malware but a medium-risk combination of broad file access and indirect prompt-injection exposure that is larger than a minimal graphing helper needs.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 13, 2026, 03:19 AM
Package URL
pkg:socket/skills-sh/debug-zhuweijian%2Fai-research-toolkit%2Fgraphify-windows%2F@60594f0d7ec2fec73bf9f88f686746780a80a6de
Security Audit — socket — graphify-windows