tuzi-format-markdown

Warn

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/autocorrect.ts script executes npx autocorrect-node, which downloads and runs a package from the npm registry at runtime.
  • [COMMAND_EXECUTION]: The skill performs shell operations in SKILL.md (such as mv and test) and scripts/autocorrect.ts (using execSync) that interpolate user-provided filenames and paths. This creates a risk of command injection if inputs are not properly sanitized.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted markdown and plain text files for analysis, summary generation, and formatting improvements. This represents a vulnerability surface where malicious instructions in the input files could potentially influence agent behavior.
  • Ingestion points: User-specified files processed in Step 1 of the SKILL.md workflow.
  • Boundary markers: None explicitly defined to separate untrusted content from agent instructions during analysis.
  • Capability inventory: File system access (read/write), shell command execution via execSync, and runtime package execution via npx.
  • Sanitization: While content is parsed via unified, typography fixes are applied through shell commands targeting the raw file path.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 8, 2026, 11:30 PM