pandoc
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
os.shell.runto invoke thepandocutility for document conversion tasks. It also provides instructions for using system package managers (brew,apt-get) to install necessary software. These actions are aligned with the skill's primary purpose and involve standard tools.\n- [EXTERNAL_DOWNLOADS]: The skill suggests installing dependencies from well-known and trusted package registries (Homebrew, APT). These are standard methods for software installation and do not involve suspicious third-party sources.\n- [PROMPT_INJECTION]: The skill is designed to process untrusted data from external files (such as DOCX, HTML, or Markdown) during conversion.\n - Ingestion points: Input file paths provided to
pandoc(e.g.,SKILL.mdcommon operations section).\n - Boundary markers: No specific boundary markers or instructions to ignore embedded content are present.\n
- Capability inventory: The skill uses
os.shell.run(SKILL.md).\n - Sanitization: No sanitization or filtering of the input file content is performed. However, because
pandocis a document converter and not an execution engine, the risk of indirect prompt injection is inherently low for this use case.
Audit Metadata