markdown-pro
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/markdown_helper.pyexecutes system commands to interact with Git. - The function
get_git_commitsusessubprocess.runto execute thegit logcommand for extracting commit metadata used in changelog generation. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The skill reads Markdown files via
scripts/markdown_helper.pyand Git commit history to generate tables of contents and changelogs. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard instructions embedded within the document content or commit messages during processing.
- Capability inventory: The skill has the capability to read and write files locally and execute shell commands via the Git CLI.
- Sanitization: The script extracts text using regular expressions but does not perform sanitization or validation of the content to prevent instruction injection before the agent processes it.
Audit Metadata