Back to skill

Security audit

Markdown Browser

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently post-processes official web fetch results and does not show hidden execution, exfiltration, persistence, or destructive behavior.

Users should be comfortable allowing this skill to process fetched page content and run a local Node script. For stronger supply-chain control, install from a reviewed lockfile or pin the turndown dependency before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Unpinned Dependencies

Low
Category
Supply Chain
Content
{"type":"module","dependencies":{"turndown":"^7.2.2"}}
Confidence
95% confidence
Finding
The dependency uses a caret range (^7.2.2), which permits automatic installation of newer compatible versions rather than a single exact version. This can introduce supply-chain risk if a future release in that range is compromised or contains a breaking security issue, though the package shown is common and the file itself does not indicate overtly malicious intent.

Static analysis

No suspicious patterns detected.