markdown-to-html

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing well-known markdown processing tools (marked, pandoc, hugo, jekyll, gomarkdown) from official package registries (NPM, RubyGems) and established system package managers (Homebrew, Chocolatey, APT).
  • [COMMAND_EXECUTION]: Includes standard CLI usage examples for various conversion tools, as well as routine installation commands for different operating systems.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external Markdown data, which is a common surface for indirect prompt injection or XSS attacks. However, the skill provides excellent security guidance, including specific recommendations to use sanitizers like DOMPurify or Bluemonday to protect against malicious payloads in processed content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 09:15 AM
Security Audit — agent-trust-hub — markdown-to-html