markitdown-document-ingestion
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
markitdownpackage viapip. This tool is an official project from a trusted organization and its inclusion is standard for the skill's documented purpose. - [COMMAND_EXECUTION]: The skill utilizes the
markitdowncommand-line interface to convert files locally. It incorporates defensive practices, such as instructing the user to inspect file counts and sizes before extracting archives to mitigate risks like path traversal or resource exhaustion. - [PROMPT_INJECTION]: The skill manages an indirect prompt injection surface by processing external document content.
- Ingestion points: External file formats (PDF, DOCX, ZIP, etc.) provided for research.
- Boundary markers: The instructions explicitly define the converted output as a non-authoritative "analysis copy."
- Capability inventory: Uses the
markitdownCLI for local file conversion; no direct network exfiltration is scripted. - Sanitization: Includes mandatory verification steps to check for anomalous output and verify the provenance of archives before conversion.
Audit Metadata