Back to skill

Security audit

baoyu-md-formatter

Security checks across malware telemetry and agentic risk

Overview

The skill is advertised as a Markdown formatter but asks for read, write, and command execution authority while documenting unrelated API, credential, and code-development workflows.

Review carefully before installing. This appears to be a broad, template-like automation skill rather than a tightly scoped Markdown formatter. Only use it if you are comfortable granting file read/write and command execution authority, and avoid providing API keys or credentials unless the exact external service and need are clear.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill is presented as a markdown formatter, but these sections expand it into API integration and system command execution. That mismatch materially increases the attack surface because a user or agent may grant exec capability under the false assumption that the skill only performs local text formatting.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The operational steps instruct the agent to read code, analyze dependencies, refactor, test, and execute development tasks unrelated to markdown formatting. This creates dangerous ambiguity that could cause an agent to perform invasive actions on arbitrary project files beyond the user's expected formatting request.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The paid-feature and FAQ content claims unrelated capabilities such as static analysis, vulnerability detection, code review, and CI/CD integration. These claims can mislead orchestration systems or users into invoking the skill in higher-risk contexts than intended, broadening privileges and trust improperly.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The quick-start and troubleshooting guidance tells users to configure API keys, establish API connections, and execute commands, which contradicts a local markdown formatter use case. This may lead users to expose credentials or authorize unnecessary external/networked behavior for a task that should not require it.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The invocation description is overly broad, covering generic file processing, conversion, and content extraction without tight boundaries. Ambiguous scope increases the chance an agent will apply the skill in unintended contexts and use its read/write/exec permissions more broadly than a simple formatter should.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill describes file processing and output generation but does not clearly warn that files may be modified or overwritten. In a write-capable skill, lack of modification warnings can cause unintended data loss or silent changes to user documents.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
These steps mention command execution and validation tooling without any explicit user warning. Because the skill advertises exec capability, omission of a warning makes it easier for an agent to run commands the user did not anticipate for a formatting task.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.