Back to skill

Security audit

qmd External Knowledge Base Search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local Markdown search helper, with disclosed local indexing and an install-time supply-chain risk users should understand.

Before installing, review the qmd upstream repository and consider pinning to a known commit or release. Only add Markdown folders you actually want indexed, and create the optional cron reindex job only if you are comfortable with recurring local indexing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Installation from a Mutable Remote Git Repository

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 5 and 27
Vulnerability Type: Supply-chain risk from an unpinned remote dependency
Risk Level: Medium

Vulnerable Code Snippet:

yaml
metadata: {"clawdbot":{"emoji":"🔍","os":["darwin","linux"],"requires":{"bins":["qmd"]},"install":[{"id":"bun-qmd","kind":"shell","command":"bun install -g https://github.com/tobi/qmd","bins":["qmd"],"label":"Install qmd via Bun"}]}}
bash
bun install -g https://github.com/tobi/qmd

Technical Analysis

The installation command retrieves and globally installs executable software directly from a mutable Git repository without pinning an audited commit hash or immutable release artifact. Consequently, the code executed at installation time may differ from the version originally reviewed.

The repository URL is consistent with the Skill's declared homepage, and there is no evidence of typosquatting or current malicious behavior. Nevertheless, compromise of the upstream repository, its maintainers, or the relevant branch could cause altered package code or installation scripts to execute with the installing user's permissions. Global installation also places the resulting executable in the user's tool path, increasing the duration and scope of exposure.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or the mutable branch resolved by the Git URL.
  2. The attacker modifies package code or lifecycle scripts while preserving expected qmd functionality or appearance.
  3. A user or agent follows the Skill's installation instruction.
  4. Bun downloads the current, attacker-controlled repository state and executes any applicable installation or lifecycle behavior.
  5. The installed qmd executable subsequently runs with the invoking user's permissions and can access resources available to that account.

Impact Assessment

Successful exploitation could permit arbitra ...[truncated 721 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin installation to a specific audited commit hash or immutable, signed release rather than a mutable repository reference.
  • Prefer a trusted package registry release that supplies integrity metadata, and verify the expected checksum or signature before installation.
  • Record the approved version and digest in the Skill documentation so installations are reproducible.
  • Review package lifecycle scripts and transitive dependencies before approving an update.
  • Avoid elevated installation privileges and run qmd under a least-privileged user with access only to collections the user explicitly selects.
  • Require explicit user confirmation before global installation or creation of a scheduled reindex task.
  • For scheduled execution, use absolute paths to the verified executable and document how to inspect and remove the task.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.