graphify
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PERSISTENCE_MECHANISMS]: The skill includes functionality to install a Git post-commit hook via
graphify hook install. This modifies the.git/hooks/post-commitfile to automatically execute code after every commit, establishing a persistence mechanism on the user's filesystem. - [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: In Step 1 of
SKILL.md, the skill attempts to install a package namedgraphifyyfrom PyPI usingpiporuv. There is a discrepancy between the skill's stated name ('graphify') and the package name it installs ('graphifyy'), which can be an indicator of typosquatting or deceptive naming. The skill subsequently executes code from this package. - [COMMAND_EXECUTION]: The skill makes extensive use of
bashblocks to execute Python code snippets viapython3 -c. This includes sensitive operations such as file system manipulation, directory traversal, and managing background processes. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided content (code, documents, images, and videos) in Step 3. It dispatches LLM subagents to analyze these files using a detailed prompt provided in
references/extraction-spec.md. The subagents are granted access to aWritetool to output results to absolute paths. The ingestion process lacks boundary markers or sanitization to prevent malicious instructions embedded in the analyzed files from influencing the subagents' behavior. - [DYNAMIC_EXECUTION]: The skill generates and executes Python scripts at runtime to handle AST extraction, semantic merging, and graph analysis. It uses a stored interpreter path in
graphify-out/.graphify_pythonto ensure consistency across multiple shell invocations.
Audit Metadata