Back to skill

Security audit

format-markdown-mkdocs

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local Markdown formatter with disclosed file edits, analysis output, backups, and npm-based formatting support; review generated edits before relying on them.

Install only if you are comfortable with a skill that can rewrite Markdown structure and metadata. Use the formatted-copy workflow for important documents, review title and summary changes because auto_select is enabled, and avoid structural-fixes-only mode unless you intentionally want the original file modified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 349)May include surrounding context.

md
Scripts are stored in the `scripts/` subdirectory. `${SKILL_DIR}` is the root directory containing this `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 365)May include surrounding context.

md
If `package-lock.json` already exists, prefer:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents shell and Node.js execution, environment-variable use (${SKILL_DIR}), file writes, backups, and package installation, but it declares no explicit tool scope or permissions boundary. This increases the chance an agent will invoke broader filesystem or command capabilities than the user expects, especially because the workflow includes in-place modification and dependency installation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest mentions summarizing and formatting, but the full documented behavior goes beyond structural formatting into editorial transformation: generating new titles, summaries, frontmatter, headings, lists, tables, admonitions, and typo corrections. This is a broader content-editing capability than a reader might infer from a markdown formatter focused on compatibility fixes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow offers a mode that modifies the original file in place, but it does not require an explicit destructive-action warning or confirmation at the point of choice. This creates a realistic risk of accidental data loss or irreversible alteration of source documents, especially when combined with automated agent execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The prohibited title patterns include specific Chinese-language phrases, which introduces a language/locale-specific policy into a generally described markdown-formatting skill. The skill does not state that it is limited to Chinese content or offer the user a language choice, so this appears to enforce a locale-specific style rule without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The prohibited summary patterns include fixed Chinese-language phrases in a skill otherwise presented as a general markdown formatter. Because no language selection or region-specific scope is documented, this creates a language/locale policy constraint without explicit user choice.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

auto_select allows the skill to make substantive editorial decisions—title and summary generation—without asking the user. In this skill context, autonomous metadata changes can alter meaning, misrepresent content, or trigger unintended publication changes, and the risk is amplified because the workflow also writes files automatically.

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

Here is the summary you generated.

text

**EXTEND.md skip behavior:** If `auto_select: true` is set in `EXTEND.md`, skip title and summary selection and generate the best candidate directly without asking. The user may also set `auto_select_title: true` or `auto_select_summary: true` independently.

---

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says the skill outputs to '{filename}_formatted.md' by default, implying creation of a separate formatted file. In code, when '--output' is not provided, the script sets the output path to the input path itself, overwriting the source file instead of producing a suffixed output file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description presents the skill as producing a formatted markdown output file by default, but the documented behavior in Step 2 additionally saves a separate analysis artifact. That extra write is part of the skill's actual operation and is not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"node": ">=18"
  },
  "dependencies": {
    "unified": "^11.0.5",
    "remark-parse": "^11.0.0",
    "remark-math": "^6.0.0",
    "remark-gfm": "^4.0.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 9)May include surrounding context.

json
},
  "dependencies": {
    "unified": "^11.0.5",
    "remark-parse": "^11.0.0",
    "remark-math": "^6.0.0",
    "remark-gfm": "^4.0.0",
    "unist-util-visit": "^5.0.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"dependencies": {
    "unified": "^11.0.5",
    "remark-parse": "^11.0.0",
    "remark-math": "^6.0.0",
    "remark-gfm": "^4.0.0",
    "unist-util-visit": "^5.0.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"unified": "^11.0.5",
    "remark-parse": "^11.0.0",
    "remark-math": "^6.0.0",
    "remark-gfm": "^4.0.0",
    "unist-util-visit": "^5.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
"remark-parse": "^11.0.0",
    "remark-math": "^6.0.0",
    "remark-gfm": "^4.0.0",
    "unist-util-visit": "^5.0.0"
  }
}

Static analysis

No suspicious patterns detected.