Back to skill

Security audit

Markdown Format Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Markdown/text formatting helper, though users should avoid in-place edits unless they intended them.

Install only if you want an agent to read and format Markdown or text files. Prefer specifying an output path instead of directly modifying the original, and treat command execution as something to use only for clearly requested local formatting steps.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger conditions are overly broad ('file processing, document conversion, format conversion, content extraction'), which can cause the skill to activate for many unrelated document tasks. In an agent ecosystem, overbroad activation increases the chance of inappropriate tool use, unexpected file access, or execution of local commands in contexts the user did not intend.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly supports directly modifying the original file but does not require confirmation, backup creation, or a dry-run preview. This creates a real integrity risk: an agent could overwrite user content, damage formatting, or alter important files without an explicit safeguard, especially because the skill also has exec capability.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.