data-graph-database
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits 'Context Stuffing' by including over 1,200 identical sections of technical technical text across eight reference files (e.g., architecture-patterns.md, error-handling.md). This volume of irrelevant content can exhaust the agent's context window and displace its system prompt or safety guardrails.\n- [PROMPT_INJECTION]: Indirect Prompt Injection Surface identified:\n
- Ingestion points: The skill instructions in SKILL.md direct the agent to ingest and analyze user-supplied domain data and query patterns.\n
- Boundary markers: Absent. The skill does not instruct the agent to use delimiters or ignore potential instructions embedded within the ingested data.\n
- Capability inventory: The skill provides implementation patterns for executing shell commands (neo4j-admin), graph queries (Cypher, Gremlin), and Python scripts for embeddings (node2vec, networkx).\n
- Sanitization: Absent. There is no guidance to validate or filter user-supplied content before it is incorporated into generated scripts or commands.
Audit Metadata