graphify
Fail
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill attempts to install a package named
graphifyyviapip install graphifyy -q --break-system-packagesif an import ofgraphifyfails. The extra 'y' in the package name is a strong indicator of typosquatting, which is used to deliver malicious code. - [COMMAND_EXECUTION]: The skill provides a command
graphify hook installthat adds apost-commitscript to the local git repository. This establishes a persistence mechanism that executes code automatically every time a user commits changes. - [COMMAND_EXECUTION]: The
graphify claude installcommand modifies the project'sCLAUDE.mdfile to inject instructions that force the AI agent to use the skill in future sessions, overriding standard agent behavior. - [PROMPT_INJECTION]: The skill processes arbitrary folders of files and external URLs (
graphify add) and passes the content directly to subagents in Step B2. The lack of sanitization or boundary markers (such as XML tags or explicit 'ignore instructions' warnings) makes the system vulnerable to indirect prompt injection from the files being analyzed. - [EXTERNAL_DOWNLOADS]: The
graphify add <url>command fetches data from arbitrary external websites and saves it to the local filesystem (./raw), which can be used to introduce malicious payloads into the analysis pipeline. - [DATA_EXFILTRATION]: The
--neo4j-pushflag facilitates sending extracted graph data—which may contain sensitive architectural details, entity relationships, and logic patterns—to a remote database URI provided by the user.
Recommendations
- AI detected serious security threats
Audit Metadata