graphify

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PERSISTENCE_MECHANISMS]: The skill includes functionality to install a Git post-commit hook via graphify hook install. This modifies the .git/hooks/post-commit file to automatically execute code after every commit, establishing a persistence mechanism on the user's filesystem.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: In Step 1 of SKILL.md, the skill attempts to install a package named graphifyy from PyPI using pip or uv. There is a discrepancy between the skill's stated name ('graphify') and the package name it installs ('graphifyy'), which can be an indicator of typosquatting or deceptive naming. The skill subsequently executes code from this package.
  • [COMMAND_EXECUTION]: The skill makes extensive use of bash blocks to execute Python code snippets via python3 -c. This includes sensitive operations such as file system manipulation, directory traversal, and managing background processes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided content (code, documents, images, and videos) in Step 3. It dispatches LLM subagents to analyze these files using a detailed prompt provided in references/extraction-spec.md. The subagents are granted access to a Write tool to output results to absolute paths. The ingestion process lacks boundary markers or sanitization to prevent malicious instructions embedded in the analyzed files from influencing the subagents' behavior.
  • [DYNAMIC_EXECUTION]: The skill generates and executes Python scripts at runtime to handle AST extraction, semantic merging, and graph analysis. It uses a stored interpreter path in graphify-out/.graphify_python to ensure consistency across multiple shell invocations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — graphify