pandoc

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses os.shell.run to invoke the pandoc utility for document conversion tasks. It also provides instructions for using system package managers (brew, apt-get) to install necessary software. These actions are aligned with the skill's primary purpose and involve standard tools.\n- [EXTERNAL_DOWNLOADS]: The skill suggests installing dependencies from well-known and trusted package registries (Homebrew, APT). These are standard methods for software installation and do not involve suspicious third-party sources.\n- [PROMPT_INJECTION]: The skill is designed to process untrusted data from external files (such as DOCX, HTML, or Markdown) during conversion.\n
  • Ingestion points: Input file paths provided to pandoc (e.g., SKILL.md common operations section).\n
  • Boundary markers: No specific boundary markers or instructions to ignore embedded content are present.\n
  • Capability inventory: The skill uses os.shell.run (SKILL.md).\n
  • Sanitization: No sanitization or filtering of the input file content is performed. However, because pandoc is a document converter and not an execution engine, the risk of indirect prompt injection is inherently low for this use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:53 PM
Security Audit — agent-trust-hub — pandoc