Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md Scripts are stored in the `scripts/` subdirectory. `${SKILL_DIR}` is the root directory containing this `SKILL.md`.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local Markdown formatter with disclosed file edits, analysis output, backups, and npm-based formatting support; review generated edits before relying on them.
Install only if you are comfortable with a skill that can rewrite Markdown structure and metadata. Use the formatted-copy workflow for important documents, review title and summary changes because auto_select is enabled, and avoid structural-fixes-only mode unless you intentionally want the original file modified.
Referenced artifact was not completely inspected
Scripts are stored in the `scripts/` subdirectory. `${SKILL_DIR}` is the root directory containing this `SKILL.md`.
Referenced artifact was not completely inspected
If `package-lock.json` already exists, prefer:
The skill documents shell and Node.js execution, environment-variable use (${SKILL_DIR}), file writes, backups, and package installation, but it declares no explicit tool scope or permissions boundary. This increases the chance an agent will invoke broader filesystem or command capabilities than the user expects, especially because the workflow includes in-place modification and dependency installation.
The manifest mentions summarizing and formatting, but the full documented behavior goes beyond structural formatting into editorial transformation: generating new titles, summaries, frontmatter, headings, lists, tables, admonitions, and typo corrections. This is a broader content-editing capability than a reader might infer from a markdown formatter focused on compatibility fixes.
The workflow offers a mode that modifies the original file in place, but it does not require an explicit destructive-action warning or confirmation at the point of choice. This creates a realistic risk of accidental data loss or irreversible alteration of source documents, especially when combined with automated agent execution.
The prohibited title patterns include specific Chinese-language phrases, which introduces a language/locale-specific policy into a generally described markdown-formatting skill. The skill does not state that it is limited to Chinese content or offer the user a language choice, so this appears to enforce a locale-specific style rule without opt-in.
The prohibited summary patterns include fixed Chinese-language phrases in a skill otherwise presented as a general markdown formatter. Because no language selection or region-specific scope is documented, this creates a language/locale policy constraint without explicit user choice.
auto_select allows the skill to make substantive editorial decisions—title and summary generation—without asking the user. In this skill context, autonomous metadata changes can alter meaning, misrepresent content, or trigger unintended publication changes, and the risk is amplified because the workflow also writes files automatically.
Here is the summary you generated.
**EXTEND.md skip behavior:** If `auto_select: true` is set in `EXTEND.md`, skip title and summary selection and generate the best candidate directly without asking. The user may also set `auto_select_title: true` or `auto_select_summary: true` independently.
---
The manifest says the skill outputs to '{filename}_formatted.md' by default, implying creation of a separate formatted file. In code, when '--output' is not provided, the script sets the output path to the input path itself, overwriting the source file instead of producing a suffixed output file.
The manifest description presents the skill as producing a formatted markdown output file by default, but the documented behavior in Step 2 additionally saves a separate analysis artifact. That extra write is part of the skill's actual operation and is not reflected in the manifest description.
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"node": ">=18"
},
"dependencies": {
"unified": "^11.0.5",
"remark-parse": "^11.0.0",
"remark-math": "^6.0.0",
"remark-gfm": "^4.0.0",
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
},
"dependencies": {
"unified": "^11.0.5",
"remark-parse": "^11.0.0",
"remark-math": "^6.0.0",
"remark-gfm": "^4.0.0",
"unist-util-visit": "^5.0.0"
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"dependencies": {
"unified": "^11.0.5",
"remark-parse": "^11.0.0",
"remark-math": "^6.0.0",
"remark-gfm": "^4.0.0",
"unist-util-visit": "^5.0.0"
}
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"unified": "^11.0.5",
"remark-parse": "^11.0.0",
"remark-math": "^6.0.0",
"remark-gfm": "^4.0.0",
"unist-util-visit": "^5.0.0"
}
}
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"remark-parse": "^11.0.0",
"remark-math": "^6.0.0",
"remark-gfm": "^4.0.0",
"unist-util-visit": "^5.0.0"
}
}
No suspicious patterns detected.