Back to skill

Security audit

QMD - Quick Markdown Search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local Markdown search helper, with a disclosed but avoidable supply-chain risk in its install command.

Install only if you are comfortable trusting the qmd upstream repository and Bun global install path. Prefer pinning the install to a reviewed commit or release, avoid sudo, and index only Markdown folders you intentionally want searchable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Remote Dependency Installed Globally from a Mutable Git Repository

Content
View full analysis
Remediation
View remediation
``` 2. Prefer a signed, versioned release from a trusted package registry when available. Pin the exact version rather than using a range or moving tag. 3. Verify downloaded artifacts using a published cryptographic checksum or signature before installation. 4. Record the reviewed version, commit hash, expected checksum, and upstream source in `SKILL.md` so installations are reproducible and auditable. 5. Use package-manager provenance or signature verification where supported, and reject installation when verification fails. 6. Avoid elevated privileges. Perform installation under a dedicated, least-privileged user account or inside a sandbox/container when practical. 7. Review dependency installation hooks and the resulting executable before recommending an updated version or commit. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.