qmd
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the dynamic command syntax in SKILL.md to execute 'qmd status' when the skill is loaded. This serves as a benign diagnostic check to inform the user if the necessary qmd CLI tool is installed.
- [EXTERNAL_DOWNLOADS]: The skill requires the @tobilu/qmd NPM package to be installed globally on the user's system. This is a core dependency for the search and indexing features described in the documentation.
- [INDIRECT_PROMPT_INJECTION]: The skill enables an agent to search and retrieve data from local markdown files, which presents a surface for indirect prompt injection.
- Ingestion points: Data enters the context through the query, get, and multi_get tools which read from local markdown collections defined in SKILL.md.
- Boundary markers: The skill does not instruct the agent to use delimiters or ignore embedded instructions within retrieved markdown content.
- Capability inventory: The agent can execute search and retrieval operations via the qmd CLI using the Bash(qmd:*) tool.
- Sanitization: The skill lacks mechanisms to sanitize or filter potential instructions embedded in the markdown files it retrieves.
Audit Metadata