Back to skill

Security audit

Markdown Lint

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate Markdown linting helper, but users should pin the tooling version and review any repository-wide edits before committing.

Before installing or using this skill, prefer a pinned markdownlint-cli2 version or a project devDependency with a committed lockfile. Run bulk --fix and horizontal-rule cleanup commands only in a clean git working tree, preview affected files where possible, and review diffs before committing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:145
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:126
Finding

Destructive Batch Repair Uses Unsafe Filename Parsing

Content
View full analysis
&1 \ | grep -E '\.md:[0-9]+:' | grep -oE '^[^:]+' | sort -u) # Remove horizontal rules in bulk while preserving frontmatter for file in $files; do awk 'NR == 1 && /^---[[:space:]]*$/ { print; fm = 1; next } fm && /^---[[:space:]]*$/ { print; fm = 0; next } !fm && /^[[:space:]]*[-*_][[:space:]]*[-*_][[:space:]]*[-*_][-*_ ]*$/ { next } { print }' "$file" > "$file.tmp" && mv "$file.tmp" "$file" echo "Fixed: $file" done ``` ### Technical Analysis The command obtains file paths by parsing human-readable diagnostics and stores them in a shell variable. The loop then expands that variable without quotes: ```bash for file in $files ``` Unquoted expansion performs shell word splitting and pathname expansion. Paths containing spaces or tabs are divided into multiple values, while path components containing wildcard characters can expand to other matching files. In addition, `grep -oE '^[^:]+'` truncates paths containing a colon. This parsing is used by a destructive operation that writes transformed content to `"$file.tmp"` and then replaces the original path with `mv`. Therefore, an incorrectly parsed or expanded path can cause the repair process to modify a file other than the file originally reported by the checker. The use of a predictable `"$file.tmp"` path also provides weaker temporary-file safety than creating an exclusive temporary file with `mktemp`. ### Attack Path 1. An attacker contributes a Markdown file whose name contains shell wildcard characters, whitespace, or a colon. 2. The file contains a horizontal rule, causing `check-horizontal-rules.sh` to include its path in diagnostic output. 3. A us ...[truncated 990 chars]
Remediation
View remediation
"$tmp"; then mv -- "$tmp" "$file" else rm -f -- "$tmp" exit 1 fi done < <(find . -name '*.md' -not -path './node_modules/*' -print0) ``` 4. If only violating files should be changed, modify the checker to emit those paths directly in a NUL-delimited format rather than extracting them with `grep`. 5. Use `--` before path operands where supported to prevent filenames beginning with a hyphen from being interpreted as options. 6. Create temporary files using `mktemp` in the destination directory and ensure cleanup occurs on failure. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (13)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill repeatedly instructs users to invoke npx markdownlint-cli2 without pinning a specific package version. npx may fetch the latest published package at execution time, which creates a supply-chain risk if a malicious or compromised release is published, especially because the command is presented as a routine prerequisite and validation step.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This instance again recommends npx markdownlint-cli2 with no version pin. In the context of an automation/setup skill, that means users may execute whatever version is current on the registry, exposing them to unexpected behavior or malicious upstream package changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents a batch-edit loop that rewrites files in place using awk and mv, but it does not give an explicit up-front warning that repository files will be modified and should be backed up or reviewed. In practice, users may paste and run the block verbatim, causing unintended content loss or large-scale edits, especially because the command targets multiple Markdown files automatically.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The --fix command uses unpinned npx, which combines automatic file modification with dynamic package resolution. If a compromised package version were fetched, it would run in a context where the user expects repository-wide edits, increasing the blast radius.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This verification command also executes an unpinned npx package from the registry. Although it appears read-only, it still runs arbitrary package code resolved at invocation time, so the main risk is supply-chain execution rather than linting behavior itself.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The monorepo-wide --fix example uses npx without version pinning, and it operates across many files. That makes a compromised upstream package especially risky because users are encouraged to run it broadly over a repository tree.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This monorepo check command still relies on unpinned remote package execution through npx. The skill context makes it more credible and likely to be copied verbatim, which increases practical exposure to registry compromise or malicious package updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The error-analysis pipeline invokes npx markdownlint-cli2 without fixing the package version. Because this is part of troubleshooting guidance, users may run it repeatedly over time, each time accepting whatever code the registry serves for the latest package version.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This file-statistics example also runs unpinned npx, preserving the same supply-chain execution risk. The surrounding shell pipeline does not itself introduce the issue; the primary problem is executing a mutable remote package identifier.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The validation step tells users to run an unpinned npx command after setup. This is a true issue because the skill normalizes executing code from the package registry without version control, creating a preventable supply-chain exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The 'check existing repo' command continues the pattern of unpinned npx execution. In a security review, this is a real but moderate-severity vulnerability because it can lead to arbitrary code execution if the upstream package or dependency chain is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This auto-fix command is the highest-risk instance of the repeated npx pattern because it both executes unpinned remote package code and intentionally modifies repository contents. A malicious or compromised release could alter files, exfiltrate data, or run arbitrary shell behavior under the user's trust.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill's primary instructional content begins in Chinese and continues with Chinese-language usage guidance, but it does not indicate that language selection is optional or based on user preference. This can violate a language/locale policy when a skill effectively forces one language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.