backnotprop/plannotator430 installs
plannotator-annotate
Open Plannotator's annotation UI for a markdown file, HTML file, URL, or folder and then respond to the returned annotations.
How do I install this agent skill?
npx skills add https://github.com/backnotprop/plannotator --skill plannotator-annotateIs this agent skill safe to install?
- Gen Agent Trust Hubwarn
The skill is vulnerable to command injection because user arguments are passed unsanitized into a shell command that executes automatically when the skill is loaded. It also contains an indirect prompt injection surface by processing external data without boundary markers.
- Socketwarn
1 alert: gptSecurity
- Snykwarn
Risk: MEDIUM · 1 issue
What does this agent skill do?
Plannotator Annotate
Markdown annotations
!plannotator annotate $ARGUMENTS
Your task
The output above will be one of:
- The exact text
The user approved., an "Approved with Notes" message, OR a JSON object with"decision": "approved". The user approved the markdown file(s). If it is the Approved with Notes message, or that object also carries a"feedback"field, the user approved with notes: read them and carry them into subsequent work — they are non-blocking guidance, not a request to revise the file. Otherwise acknowledge with a single sentence ("Approved.") and stop. Either way, do not begin any work. - Empty, OR a JSON object with
"decision": "dismissed". The user closed the session without requesting changes. Acknowledge with a single sentence ("Annotation session closed.") and stop. Do not begin any work. - Plaintext annotation feedback, OR a JSON object with
"decision": "annotated"and a"feedback"field. Address the feedback. The user has reviewed the markdown file(s) and provided specific annotations and comments. - A message that the arguments could not be resolved to a file, URL, or folder. The user described what to annotate in natural language: work out which file, URL, or folder they mean, run
plannotator annotate <path-or-url>yourself with that concrete target (keeping any flags the message echoes), then handle its output per cases 1-3.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/backnotprop/plannotator/plannotator-annotate">View plannotator-annotate on skillZs</a>