pdf-to-markdown

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the markitdown package from PyPI using the uvx tool. This package is maintained by Microsoft, an established and trusted organization.
  • [COMMAND_EXECUTION]: Executes shell commands to perform document conversion. The instructions specify using the uvx runner to execute the markitdown utility with appropriate dependency extras for PDF, Word, Excel, and PowerPoint files.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external files during conversion. While the tool itself is safe, the resulting Markdown text may contain instructions embedded within the source documents that could influence an agent's behavior if processed subsequently without review.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 03:55 AM
Security Audit — agent-trust-hub — pdf-to-markdown