Back to skill

Security audit

QMD — Quality Markdown Formatter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local document search helper; the main caution is that it installs its CLI from an unpinned GitHub source.

Install this only if you are comfortable trusting the referenced qmd GitHub project and its future updates. When using it, add only the directories you intend to search, avoid indexing sensitive folders, and be aware that indexed content is stored under ~/.cache/qmd by default.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party GitHub Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Unpinned dependency from a mutable remote repository
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"clawdbot":{"emoji":"📝","requires":{"bins":["qmd"]},"install":[{"id":"node","kind":"node","package":"https://github.com/tobi/qmd","bins":["qmd"],"label":"Install qmd (node)"}]}}

Technical Analysis

The installation configuration references a GitHub repository URL without pinning an immutable commit, versioned release, or verified artifact checksum. Consequently, the code installed from this location can change after the Skill has been reviewed.

The dependency's executable source is not included in the audited artifact, so its implementation and transitive dependencies could not be verified. Although the audit found no evidence that the current upstream project is malicious, relying on a mutable source creates a supply-chain risk. Compromise of the upstream repository, its publishing workflow, or its dependency chain could cause future installations to receive altered code.

Attack Path

  1. An attacker compromises the referenced repository, a maintainer account, its release workflow, or a relevant transitive dependency.
  2. The attacker modifies the code resolved through the mutable GitHub URL.
  3. A user installs the Skill's required qmd executable using the declared installation configuration.
  4. The altered dependency is installed and subsequently executed when the Agent invokes qmd.
  5. The malicious process operates with the privileges of the user running the Agent and can attempt to access resources available to that user.

Impact Assessment

Successful exploitation could result in arbitrary code execution with the installing or invoking user's privileges. Because the documented tool indexes and retrieves local files, uses a cache under ~/.cache/qmd, communicates with an Ollama endpoint, and supports ...[truncated 416 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an immutable, reviewed commit hash or a specific signed release rather than a mutable repository URL.
  2. Verify downloaded artifacts with a published SHA-256 checksum or supported package-integrity mechanism before installation.
  3. Prefer a trusted package registry that supports immutable versions, provenance attestations, and integrity metadata.
  4. Lock all transitive dependency versions and use reproducible installation procedures.
  5. Enable repository branch protection, signed tags or commits, protected release workflows, and multi-factor authentication for maintainers.
  6. Perform dependency and source-code scanning on the exact pinned revision before approving updates.
  7. Run the executable with least privilege and restrict its filesystem and network access to only the documents, cache directory, Ollama endpoint, and MCP interfaces required for operation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.