markitdown-document-ingestion

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the markitdown package via pip. This tool is an official project from a trusted organization and its inclusion is standard for the skill's documented purpose.
  • [COMMAND_EXECUTION]: The skill utilizes the markitdown command-line interface to convert files locally. It incorporates defensive practices, such as instructing the user to inspect file counts and sizes before extracting archives to mitigate risks like path traversal or resource exhaustion.
  • [PROMPT_INJECTION]: The skill manages an indirect prompt injection surface by processing external document content.
  • Ingestion points: External file formats (PDF, DOCX, ZIP, etc.) provided for research.
  • Boundary markers: The instructions explicitly define the converted output as a non-authoritative "analysis copy."
  • Capability inventory: Uses the markitdown CLI for local file conversion; no direct network exfiltration is scripted.
  • Sanitization: Includes mandatory verification steps to check for anomalous output and verify the provenance of archives before conversion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 AM
Security Audit — agent-trust-hub — markitdown-document-ingestion