refine-markdown-to-mkdocs

Security checks across malware telemetry and agentic risk

Overview

This is a local note-refinement skill that rewrites notes into MkDocs-style Markdown and saves generated files, with no evidence of hidden code, credential access, network use, or destructive behavior.

Install this if you want an agent to transform reading or study notes into refined MkDocs-style files. Review the proposed plan before approving refinement, and keep important originals backed up because the output may merge, rewrite, or omit low-value material.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description contains broad activation phrases such as 'clean up notes' and 'summarize reading' that are common, everyday requests. This can cause the skill to trigger in situations broader than intended, leading users into a workflow that rewrites content, asks for category classification, and may modify files unexpectedly.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to save plan and refined outputs and back up existing files, but it does not require a user-facing warning or explicit consent before file creation or modification. In practice, this can lead to unintended writes, overwrites, or accumulation of backup files during what a user may perceive as a purely analytical or formatting task.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal