baoyu-format-markdown
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-supplied text or markdown files to analyze structure, extract insights, and generate summaries or optimized titles.
- Ingestion points:
SKILL.md(Steps 1 through 4) reads full file content directly into the agent context for processing. - Boundary markers: Absent. No specific delimiters or instructions are used to shield the LLM from executing commands that might be hidden inside the target files.
- Capability inventory: The skill writes new files to disk (
{filename}-analysis.md,{filename}-formatted.md) and executes text formatting scripts. - Sanitization: Absent. Input content is processed directly by the model without escaping or filtering.
- [COMMAND_EXECUTION]:
scripts/autocorrect.tsexecutes a system process viaspawnSyncto callnpx autocorrect-node. While the arguments are passed as an array to prevent shell command injection, it relies on dynamically fetching an unpinned tool from the package manager registry at runtime.
Audit Metadata