Markdown Studio

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Markdown document generator with normal file-output and image-handling behavior for its purpose.

Install this only where generating Markdown files is expected. Specify the output filename, review generated content before sharing, avoid embedding private images unless intended, and remove remote shields.io badges if the document must not contact third-party services when rendered.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger conditions include very broad, common requests such as 'Write a Markdown document', 'Generate README', and 'Create a report', which can cause the skill to activate in many normal conversations without clear user intent to invoke this specific skill. Over-broad activation increases the chance of unintended file generation or execution of the embedded Python workflow in contexts where the user only wanted general writing help.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal