Skip to main content

OpenGraph Security & Graph Export

SquireX treats Open Graph Protocol (OGP) metadata as an attack surface for headless agents. When agents browse URLs, the OGP tags on those pages can be weaponized to manipulate agent behavior.

OpenGraph Security Rules​

OG-01: OGP Metadata Prompt Injection​

FieldValue
IDAGENTFORCE-OG-01
SeverityCritical
CategoryOpenGraph Security

Detects prompt injection patterns in og:description and og:title tags on agent-reachable external endpoints. Reuses the existing adversarial patterns library to catch system prompt overrides, role hijacking, and instruction injection embedded in OGP metadata.


OG-02: A2A Agent Card / OGP Trust Mismatch​

FieldValue
IDAGENTFORCE-OG-02
SeverityHigh
CategoryOpenGraph Security

Detects discrepancies between an A2A Agent Card's signed capability claims and the OGP metadata served at the same URL. If the OGP tags advertise capabilities not declared in the agent card, a headless agent may be deceived into trusting the endpoint beyond its actual capability scope.


OG-03: Attractive Metadata Attack​

FieldValue
IDAGENTFORCE-OG-03
SeverityMedium
CategoryOpenGraph Security

Based on NeurIPS 2025 research, detects "Attractive Metadata" patterns that manipulate LLM tool selection. When OGP tags contain imperative verbs ("MUST use", "ALWAYS select") or superlative claims ("best", "most powerful"), they can bias an LLM planner to preferentially select a malicious tool over legitimate alternatives.

Graph Export​

SquireX can export the Semantic Graph — the full dependency map of your Agentforce deployment — in three formats:

DOT (Graphviz)​

squireinterp graph-export scan-request.json --format dot --output graph.dot
dot -Tpng graph.dot -o graph.png

Produces a Graphviz DOT file with:

  • Nodes colored by type (Agent, Topic, GenAiFunction, MCPServer, etc.)
  • Violation hotspots highlighted in red
  • Edges labeled with relationship types

Mermaid (GitHub)​

squireinterp graph-export scan-request.json --format mermaid

Produces a Mermaid diagram embeddable directly in GitHub PRs and READMEs:

  • Violation nodes prefixed with 🔴
  • Compatible with GitHub's native Mermaid rendering

OpenGraph HTML​

squireinterp graph-export scan-request.json --format html --output report.html

Generates a self-contained HTML file with:

  • Open Graph Protocol meta tags (shareable on Slack, Teams, etc.)
  • Auto-generated og:title and og:description from scan results
  • D3.js force-directed graph visualization
  • Interactive zoom, drag, and hover
  • Severity stats dashboard (Critical / High / Medium)

The HTML file requires no backend — open it directly in a browser or host it on any static server.