Back to skill

Security audit

Qmd

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local Markdown search helper, with the main caution being its global install of an unpinned GitHub dependency.

Install only if you trust the qmd upstream project and are comfortable with a global Bun-installed command. Add only the specific Markdown folders you want searchable, review any scheduled update/embed jobs before enabling them, and consider using an isolated environment or a pinned reviewed revision for higher assurance.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Remote Dependency Installed Globally from a Mutable Git Repository

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 4; repeated at line 30
Vulnerability Type: Unpinned third-party dependency from an unsafe mutable source
Risk Level: Medium

Vulnerable code snippet:

yaml
metadata: {"clawdbot":{"emoji":"🔍","os":["darwin","linux"],"requires":{"bins":["qmd"]},"install":[{"id":"bun-qmd","kind":"shell","command":"bun install -g https://github.com/tobi/qmd","bins":["qmd"],"label":"Install qmd via Bun"}]}}

The installation instruction is repeated later as:

bash
bun install -g https://github.com/tobi/qmd

Technical Analysis

The Skill instructs the environment to install QMD globally and directly from a GitHub repository URL. The source is not pinned to an immutable commit hash or a cryptographically verified release artifact. Consequently, the code installed when this command is executed may differ from the code that existed when the Skill was reviewed.

Because this is a global Bun installation, package installation hooks and subsequently invoked QMD code execute with the privileges of the user running Bun. The audit found no evidence that the current Skill itself contains a malicious payload; the risk arises from the mutable external dependency and its transitive supply chain.

Attack Path

  1. An attacker compromises the upstream QMD repository, a maintainer account, or a dependency used by the package.
  2. The attacker modifies the repository's default revision or installation behavior to include malicious code.
  3. A user or agent follows the Skill's installation instruction: bun install -g https://github.com/tobi/qmd.
  4. Bun downloads the modified, attacker-controlled content because no immutable revision or integrity value is specified.
  5. Malicious lifecycle code may execute during installation, or attacker-controlled logic may execute when the installed qmd command is later invoked.
  6. The payload operates with the invoking user's ...[truncated 766 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the installation to a reviewed, immutable commit hash or a specific trusted release instead of the repository's mutable default revision.
  2. Prefer an official release artifact with a published cryptographic checksum or signature, and verify its integrity before installation.
  3. Record and audit the complete transitive dependency graph using an appropriate lockfile.
  4. Avoid global installation where possible. Install the tool in an isolated project, container, sandbox, or dedicated low-privilege environment.
  5. Disable package lifecycle scripts during installation when they are unnecessary and supported by the package manager.
  6. Review upstream source changes before updating the pinned revision, and use automated dependency and provenance scanning.
  7. Run QMD with access limited to the specific document collections required for the task, rather than granting broad filesystem access.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.