skills/kevinzai/cc-commander/graphify/Gen Agent Trust Hub

graphify

Fail

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to run pip install graphifyy. This package name contains a double 'y', which deviates from the skill name ('graphify') and the linked GitHub repository ('graphify'). This pattern is typical of typosquatting, a technique used to trick users into installing malicious packages that impersonate legitimate tools.
  • [COMMAND_EXECUTION]: After package installation, the skill requires running graphify install. This command is opaque and its specific actions—such as downloading additional binaries, modifying shell profiles, or altering system configurations—are not disclosed, posing a risk of undocumented system changes.
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze entire codebases, including documents, PDFs, and images, using 'Claude subagents'. This architecture is vulnerable to indirect prompt injection, where an attacker could embed malicious instructions in project files to hijack the subagents' behavior, manipulate the resulting knowledge graph, or exfiltrate data from the environment.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 8, 2026, 02:29 PM
Security Audit — agent-trust-hub — graphify