baoyu-format-markdown
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill performs file processing by executing local scripts and established CLI utilities via shell commands.
- Evidence: The main workflow in
SKILL.mdexecutes the entry point script usingnpx -y bun ${SKILL_DIR}/scripts/main.ts. - Evidence:
scripts/autocorrect.tsusesexecSyncto runnpx autocorrect-node --fix "${filePath}"for typography adjustments. - [EXTERNAL_DOWNLOADS]: The skill uses the
npxpackage runner, which may fetch theautocorrect-nodeutility and other dependencies from the official NPM registry during execution. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect injection as it reads and analyzes untrusted user content to generate summaries and titles.
- Ingestion points:
SKILL.mdworkflow Step 1 (Read Source File) reads user-specified markdown or plain text files. - Boundary markers: No specific delimiters or "ignore" instructions are used when passing the content to the agent for structural analysis.
- Capability inventory: The skill possesses file read/write access and the ability to execute subprocesses via
execSyncandnpx. - Sanitization: The input content is processed for formatting but not sanitized against embedded instructions before the agent performs metadata extraction (summaries/titles).
Audit Metadata