Back to skill

Security audit

Baoyu Format Markdown

Security checks across malware telemetry and agentic risk

Overview

This markdown-formatting skill requests shell-command access and uses broad, generic execution instructions that do not fit its narrow stated purpose.

Review before installing. The skill does not show malicious behavior, but it asks for command execution and gives broad generic instructions for a task that should usually only need reading and editing markdown. Install only if you are comfortable with that authority or after the publisher narrows the tool access and instructions to markdown formatting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill advertises only markdown/plain-text formatting, yet it requests the `exec` tool, which enables arbitrary shell command execution. In this context the documentation also includes operational command guidance like running `ping`, making it easier for a loosely constrained agent to execute system commands unrelated to formatting, increasing the attack surface for command execution or environment probing.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The body of the skill is materially broader than its stated purpose, describing generic instruction parsing, execution, data processing, and result output rather than markdown formatting behavior. This mismatch can cause an agent to treat the skill as a general-purpose executor, which is especially risky because the skill also has `exec` capability, enabling actions outside the expected trust boundary of a formatting tool.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The activation scope extends beyond markdown formatting into broad marketing, growth, and conversion scenarios, which are unrelated to the claimed function of the skill. Overbroad invocation criteria increase the chance that an agent will select this skill in inappropriate contexts and then apply its generic execution behavior or shell access to tasks users did not intend to authorize.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The capability coverage section repeats catch-all language indicating the skill covers many loosely defined scenarios, without operational boundaries or safety constraints. In combination with generic processing language and command execution capability, this broadens the effective authority of the skill and raises the risk of misuse, prompt confusion, or unintended execution paths.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.