coding-markdown

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill triggers on the creation or modification of external markdown files, project documentation, and rules. This ingestion of potentially untrusted data constitutes an indirect prompt injection surface. However, the skill's impact is restricted to enforcing text formatting styles.
  • Ingestion points: Triggered by modifications to .md files, SKILL.md files, and rules files located in .kilocode/rules*/.
  • Boundary markers: None provided to distinguish between the skill's formatting instructions and potentially malicious instructions within the markdown files being edited.
  • Capability inventory: The skill is restricted to defining markdown formatting standards; no network operations, subprocess execution, or sensitive file access capabilities are defined.
  • Sanitization: No explicit sanitization or validation of the markdown content is performed.
  • [NO_CODE]: The skill consists entirely of markdown instructions and metadata. It does not include any executable scripts or binary files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:05 AM
Security Audit — agent-trust-hub — coding-markdown