tuzi-format-markdown
Warn
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/autocorrect.tsscript executesnpx autocorrect-node, which downloads and runs a package from the npm registry at runtime. - [COMMAND_EXECUTION]: The skill performs shell operations in
SKILL.md(such asmvandtest) andscripts/autocorrect.ts(usingexecSync) that interpolate user-provided filenames and paths. This creates a risk of command injection if inputs are not properly sanitized. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted markdown and plain text files for analysis, summary generation, and formatting improvements. This represents a vulnerability surface where malicious instructions in the input files could potentially influence agent behavior.
- Ingestion points: User-specified files processed in Step 1 of the
SKILL.mdworkflow. - Boundary markers: None explicitly defined to separate untrusted content from agent instructions during analysis.
- Capability inventory: File system access (read/write), shell command execution via
execSync, and runtime package execution vianpx. - Sanitization: While content is parsed via
unified, typography fixes are applied through shell commands targeting the raw file path.
Audit Metadata