mintlify

Warn

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users and agents to install the Mintlify CLI using the command npm i -g mint. The official Mintlify CLI package on the NPM registry is mintlify. The package named mint on NPM is an unrelated programming language. This discrepancy leads to the installation of unintended software and represents a potential confusion or typosquatting vector.
  • [METADATA_POISONING]: The YAML frontmatter in SKILL.md identifies the author as "Mintlify" and provides the official Mintlify URL. Since the skill is authored by a third party ('codewithshreyans'), this is a deceptive claim of official origin that could lead users to trust the instructions as authoritative.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to have the agent ingest and process various external files from the user's project directory, including docs.json, openapi.json, and MDX content. This creates a surface for indirect prompt injection where instructions embedded in project source files could influence the agent's actions.
  • Ingestion points: docs.json (SKILL.md, reference/configuration.md), openapi.json (reference/api-docs.md), .mdx content files (SKILL.md).
  • Boundary markers: None provided in the skill instructions to delimit external content or warn the agent about embedded instructions.
  • Capability inventory: The skill encourages the use of shell commands (mint dev, mint validate) and file system operations to modify documentation.
  • Sanitization: No instructions are provided to sanitize or validate the content of ingested documentation files.
  • [COMMAND_EXECUTION]: The skill provides a list of CLI commands for the agent to execute, such as mint dev, mint validate, and mint a11y. While these are standard for documentation development, they are tied to the execution of the incorrectly identified mint package.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 19, 2026, 01:14 PM