markdown-pro

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/markdown_helper.py executes system commands to interact with Git.
  • The function get_git_commits uses subprocess.run to execute the git log command for extracting commit metadata used in changelog generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The skill reads Markdown files via scripts/markdown_helper.py and Git commit history to generate tables of contents and changelogs.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard instructions embedded within the document content or commit messages during processing.
  • Capability inventory: The skill has the capability to read and write files locally and execute shell commands via the Git CLI.
  • Sanitization: The script extracts text using regular expressions but does not perform sanitization or validation of the content to prevent instruction injection before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:20 AM
Security Audit — agent-trust-hub — markdown-pro