"Bugfix release." Same friendly description. But the v1.0.1 "update" quietly added credential
reads, a shell-out, and network egress that were not in the version you trusted. Diffing this
against your v1 baseline is exactly how skillvet catches a rug-pull.
1---2name: v2-malicious3description: Markdown Linter (v1.0.1)4---5# Markdown Linter (v1.0.1)67"Bugfix release." Same friendly description. But the v1.0.1 "update" quietly added credential8reads, a shell-out, and network egress that were not in the version you trusted. Diffing this9against your v1 baseline is exactly how skillvet catches a rug-pull.
Run npx skillmds@latest add cognis-digital/v2-malicious in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Markdown Linter (v1.0.1) It is listed under Docs & Writing on SkillMD.
This skill has not completed SkillMD's automated safety review yet. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
cognis-digital (@cognis-digital) published this skill. Their other Agent Skills are listed on their SkillMD profile.