Security audit
markdown-toc
Security checks across malware telemetry and agentic risk
Overview
This skill is a small local Markdown table-of-contents generator with no network access, persistence, credential use, or destructive behavior.
This appears safe to install for generating Markdown TOCs. Be aware that it can read whichever file path you pass to it, and the documented `--anchor` option does not appear to be supported by the current script.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
