skills/benoror/obsidianos_work/qmd/Gen Agent Trust Hub

qmd

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @tobilu/qmd package globally via NPM. This is an external dependency from a third-party publisher required for the skill's core functionality.
  • [COMMAND_EXECUTION]: The skill requests permission to execute the qmd command through Bash. This allows the agent to perform local searches and retrieve document contents via the CLI.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests and processes untrusted content from the user's local markdown vault.
  • Ingestion points: Data is retrieved from local markdown files via qmd query, qmd get, and qmd multi_get as defined in SKILL.md and references/mcp-setup.md.
  • Boundary markers: There are no boundary markers or specific instructions to ignore instructions embedded within the retrieved file contents.
  • Capability inventory: The skill can execute the qmd CLI tool and read data from the local file system.
  • Sanitization: The skill does not perform any sanitization or validation of the markdown content before presenting it to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 05:36 PM
Security Audit — agent-trust-hub — qmd