Back to skill

Security audit

markdown-publish

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it can publish Markdown to a public, hard-to-change URL without requiring an explicit final confirmation.

Install only if you are comfortable with the agent sending Markdown to a public third-party URL. Before each publish, verify the file contains no secrets, private data, customer information, or confidential material, and prefer requiring an explicit confirmation before the curl command is run.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation description is broad enough to trigger public publication in common contexts like 'share' or 'get a link' without sufficiently strong gating around user intent, data sensitivity, or confirmation. Because the service is explicitly public, unauthenticated, and effectively irreversible, an overly eager invocation path can cause unintended disclosure of generated or user-provided content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This skill transmits file contents to an external third-party endpoint over the network, which creates a real data exfiltration channel if the content includes secrets, personal data, or confidential material. The risk is heightened by the fact that publication is public, requires no authentication, and cannot be edited after posting, so accidental disclosure may be difficult to mitigate.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: markdown-publish
description: Publishes Markdown to a public URL and returns the link. Use when the user asks to share, publish, host, or get a link for a page — or when you have produced a long page that is better delivered as a link than pasted inline. No authentication required. Pages are public and cannot be edited after publishing, so do not publish secrets or private data.
compatibility: Requires curl and network access to https://markdown.page.
---

# Publish Markdown

Static analysis

No suspicious patterns detected.