qmd
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@tobilu/qmdpackage globally via NPM. This is an external dependency from a third-party publisher required for the skill's core functionality. - [COMMAND_EXECUTION]: The skill requests permission to execute the
qmdcommand through Bash. This allows the agent to perform local searches and retrieve document contents via the CLI. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests and processes untrusted content from the user's local markdown vault.
- Ingestion points: Data is retrieved from local markdown files via
qmd query,qmd get, andqmd multi_getas defined inSKILL.mdandreferences/mcp-setup.md. - Boundary markers: There are no boundary markers or specific instructions to ignore instructions embedded within the retrieved file contents.
- Capability inventory: The skill can execute the
qmdCLI tool and read data from the local file system. - Sanitization: The skill does not perform any sanitization or validation of the markdown content before presenting it to the agent.
Audit Metadata