graphify

Fail

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill attempts to install a package named graphifyy via pip install graphifyy -q --break-system-packages if an import of graphify fails. The extra 'y' in the package name is a strong indicator of typosquatting, which is used to deliver malicious code.
  • [COMMAND_EXECUTION]: The skill provides a command graphify hook install that adds a post-commit script to the local git repository. This establishes a persistence mechanism that executes code automatically every time a user commits changes.
  • [COMMAND_EXECUTION]: The graphify claude install command modifies the project's CLAUDE.md file to inject instructions that force the AI agent to use the skill in future sessions, overriding standard agent behavior.
  • [PROMPT_INJECTION]: The skill processes arbitrary folders of files and external URLs (graphify add) and passes the content directly to subagents in Step B2. The lack of sanitization or boundary markers (such as XML tags or explicit 'ignore instructions' warnings) makes the system vulnerable to indirect prompt injection from the files being analyzed.
  • [EXTERNAL_DOWNLOADS]: The graphify add <url> command fetches data from arbitrary external websites and saves it to the local filesystem (./raw), which can be used to introduce malicious payloads into the analysis pipeline.
  • [DATA_EXFILTRATION]: The --neo4j-push flag facilitates sending extracted graph data—which may contain sensitive architectural details, entity relationships, and logic patterns—to a remote database URI provided by the user.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — graphify