Back to skill

Security audit

Markdown编辑工具

Security checks for vulnerabilities and agentic risk

Overview

This Markdown skill is not clearly malicious, but it requests broad file and command access without tight limits and contains hidden characters in an example, so it needs review before installation.

Review this before installing. Use it only in an environment where command execution is disabled or requires explicit approval, limit file access to the workspace documents you intend to process, and treat API or command-execution claims as unimplemented until the publisher documents exact commands, destinations, and user controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:35
Finding

Unnecessary Arbitrary Command-Execution Permission

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 35–38
Vulnerability Type: Excessive tool permissions and violation of least privilege
Risk Level: Medium

Vulnerable Code

yaml
tools:
  - read
  - exec
  - write

Technical Analysis

The skill declares access to the unrestricted exec tool even though its documented functions are Markdown normalization, HTML-to-Markdown conversion, linting, and table-of-contents generation. These content-processing operations do not inherently require arbitrary system command execution.

The package contains only SKILL.md and provides no implementation that justifies this permission, no command allowlist, no argument validation mechanism, and no constrained execution interface. Granting exec therefore expands the skill's authority beyond its stated operational requirements and violates the principle of least privilege.

The permission declaration is not itself proof that a malicious command will execute automatically. Exploitation depends on the hosting agent granting the requested tool and subsequently invoking it, such as after interpreting attacker-controlled document content as instructions.

Attack Path

  1. A user installs or loads the skill in an agent environment that grants the tools declared in SKILL.md.
  2. The agent receives attacker-controlled Markdown, HTML, or plain text for conversion or linting.
  3. The input contains instructions crafted to influence the agent into invoking a system command.
  4. Because the skill unnecessarily has access to exec, the agent may issue the command rather than limiting its actions to in-memory content transformation.
  5. The command executes with the operating-system and sandbox privileges available to the agent.

Impact Assessment

Successful exploitation could allow execution of arbitrary commands within the agent's security context. Depending on sandboxing, filesystem permissions, and available credentials, this may permit reading ...[truncated 399 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec from the declared tools:
    yaml
    tools:
      - read
      - write
    
  2. For transformations performed entirely on supplied content, consider removing all tool permissions and returning the transformed Markdown directly.
  3. If filesystem processing is required, restrict read and write to an explicit workspace directory and prevent path traversal or access to sensitive files.
  4. If external lint execution is genuinely necessary, replace arbitrary exec access with a dedicated operation that invokes a fixed executable.
  5. Use a strict argument array rather than shell-string construction, validate all options against an allowlist, and never interpolate document content into commands.
  6. Run any necessary formatter or linter in a sandbox with restricted filesystem, network, environment-variable, and process permissions.
  7. Require explicit user confirmation before executing commands and treat all Markdown, HTML, and plain-text input as untrusted data rather than agent instructions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
87% confidence
Finding

The manifest combines broad descriptive language, powerful tool declarations (read/exec/write), and hidden-character indicators, which together are consistent with tool/metadata poisoning risk. While not a proof of exploitation by itself, this metadata can mislead the agent about the skill's intended authority and cause unsafe tool selection or over-privileged execution during benign Markdown tasks.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
---

slug: markdown
name: "markdown"
version: 1.0.3
displayName: "Markdown编辑工具"
summary: "生成干净可移植Markdown,跨解析器正确渲染。Generate clean, portable Markdown that renders correctly across parser"
summary_zh: "生成干净可移植Markdown,跨解析器正确渲染。Generate clean, portable Markdown that renders correctly across parser"
license: "MIT"
description: |-
  Generate clean, portable Markdown that renders correctly across parsers。核心能力:

  - 其他工具领域的专业化AI辅助工具

  - 

  - 

  适用场景:

  - 通用工具、辅助功能、扩展能力

  - 独立开发者与一人公司效率提升

  - 自动化工作流与智能决策辅助
tags:
  - Other
  - Markdown
  - 文档
  - 工具
  - markdown
  - html
  - toc
  - github
tools:
  - read
  - exec
  - write
homepage: ""
category: "Development"
homepage: ""
pricing_tier: "L2-标准级"

---

> **功能说明**: 本技

Hidden Instructions

High
Category
Prompt Injection
Confidence
96% confidence
Finding

The sample output includes hidden/non-printing characters around a fenced code block, which is a classic prompt/markup obfuscation technique. In agent-consumed skill files, hidden characters can conceal instructions from reviewers while still influencing model parsing or downstream tooling, enabling stealthy prompt injection or behavior manipulation.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
- 列表项1
- 列表项2

​```python
print("hello")
​```
# 请参考上方使用说明进行配置和调用

Hidden Instructions

High
Category
Prompt Injection
Confidence
98% confidence
Finding

A second hidden-character occurrence appears adjacent to unrelated imperative text and a result assignment embedded in what should be a Markdown example. This increases suspicion of deliberate concealment intended to smuggle instructions or payload-like content into the skill, potentially biasing agent behavior beyond the declared Markdown functionality.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

​python print("hello") ​

请参考上方使用说明进行配置和调用

result = "ready"

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a broad, loosely scoped skill with powerful tools but without clear activation boundaries or limitations. Overbroad capability descriptions increase the chance an agent invokes read/exec/write functionality outside the user's intended Markdown-only task, enabling prompt-scope creep and unnecessary access to files or commands.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'normalized Markdown' example contains extraneous code/output that is not valid for the documented transformation and appears to inject unrelated instructions/results into the sample output. In an agent skill, misleading examples can shape model behavior and cause it to emit or preserve hidden operational content instead of only producing sanitized Markdown.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises file processing, API integration, and command execution, but does not present strong user-facing warnings or guardrails about modification, data exfiltration, or system effects. In an agent context, this can normalize dangerous tool use and lead to unintended writes, command execution, or transmission of sensitive content during routine formatting tasks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Most of the user-facing documentation and examples are written in Chinese, while the skill is presented as generally applicable across agents and environments. There is no statement that users may choose their preferred language or locale, which may conflict with organizational language-choice expectations for broadly scoped skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.