baoyu-format-markdown

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs file processing by executing local scripts and established CLI utilities via shell commands.
  • Evidence: The main workflow in SKILL.md executes the entry point script using npx -y bun ${SKILL_DIR}/scripts/main.ts.
  • Evidence: scripts/autocorrect.ts uses execSync to run npx autocorrect-node --fix "${filePath}" for typography adjustments.
  • [EXTERNAL_DOWNLOADS]: The skill uses the npx package runner, which may fetch the autocorrect-node utility and other dependencies from the official NPM registry during execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect injection as it reads and analyzes untrusted user content to generate summaries and titles.
  • Ingestion points: SKILL.md workflow Step 1 (Read Source File) reads user-specified markdown or plain text files.
  • Boundary markers: No specific delimiters or "ignore" instructions are used when passing the content to the agent for structural analysis.
  • Capability inventory: The skill possesses file read/write access and the ability to execute subprocesses via execSync and npx.
  • Sanitization: The input content is processed for formatting but not sanitized against embedded instructions before the agent performs metadata extraction (summaries/titles).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:09 AM