mintlify
Warn
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users and agents to install the Mintlify CLI using the command
npm i -g mint. The official Mintlify CLI package on the NPM registry ismintlify. The package namedminton NPM is an unrelated programming language. This discrepancy leads to the installation of unintended software and represents a potential confusion or typosquatting vector. - [METADATA_POISONING]: The YAML frontmatter in
SKILL.mdidentifies the author as "Mintlify" and provides the official Mintlify URL. Since the skill is authored by a third party ('codewithshreyans'), this is a deceptive claim of official origin that could lead users to trust the instructions as authoritative. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to have the agent ingest and process various external files from the user's project directory, including
docs.json,openapi.json, and MDX content. This creates a surface for indirect prompt injection where instructions embedded in project source files could influence the agent's actions. - Ingestion points:
docs.json(SKILL.md, reference/configuration.md),openapi.json(reference/api-docs.md),.mdxcontent files (SKILL.md). - Boundary markers: None provided in the skill instructions to delimit external content or warn the agent about embedded instructions.
- Capability inventory: The skill encourages the use of shell commands (
mint dev,mint validate) and file system operations to modify documentation. - Sanitization: No instructions are provided to sanitize or validate the content of ingested documentation files.
- [COMMAND_EXECUTION]: The skill provides a list of CLI commands for the agent to execute, such as
mint dev,mint validate, andmint a11y. While these are standard for documentation development, they are tied to the execution of the incorrectly identifiedmintpackage.
Audit Metadata