markdown-pipeline

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides defensive programming guidelines for developers building markdown processing pipelines. It explicitly instructs the agent to highlight XSS risks and enforce sanitization using tools like rehype-sanitize.- [DYNAMIC_EXECUTION]: The instructions contain proactive security constraints, explicitly warning never to suggest eval() or arbitrary component mapping from URL parameters, which are common vectors for code injection.- [DATA_EXPOSURE]: No evidence of sensitive file access or unauthorized data exfiltration was found. The skill includes links to the author's own GitHub repository and NPM package, which are consistent with the skill's metadata and purpose.- [COMMAND_EXECUTION]: The skill operates within a read-only tool scope and does not include any shell command execution or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 03:03 AM
Security Audit — agent-trust-hub — markdown-pipeline