graphify
Audited by Socket on Aug 26, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the skill is largely aligned with codebase graph analysis, but its footprint is broad. The main concerns are automatic third-party tool installation and high indirect prompt-injection exposure from processing untrusted external content with concurrent write/exec capabilities. No strong evidence of credential theft or overtly malicious data routing was found.
The code documents legitimate local graph querying and result storage. It contains no clear malware, data exfiltration, credential theft, or destructive behavior. However, its command-construction pattern can introduce command or code injection when user questions, answers, or node names are substituted without robust escaping. This is a security design risk, not sufficient evidence of intentional malicious behavior.