markitright
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PDF documents provided by users, which serves as a primary ingestion point for content that could potentially contain adversarial instructions aimed at influencing the agent's behavior during conversion or quality assurance phases.
- Ingestion points:
INPUT.pdfvia themarkitrightCLI andscripts/check_page.sh(referenced inSKILL.md). - Boundary markers: The instructions do not define specific delimiters or warnings for the agent to ignore instructions embedded within the processed PDF content.
- Capability inventory: The skill has the ability to execute shell commands (
markitright,scripts/check_page.sh), perform file system writes (markdown output and figures), and make network requests (Gemini API via CLI). - Sanitization: No explicit sanitization or filtering of the PDF content is described in the provided instructions.
- [COMMAND_EXECUTION]: The skill requires the execution of local command-line tools and shell scripts to perform its primary functions.
- Evidence: Execution of
markitright INPUT.pdf -o OUTPUT.mdandscripts/check_page.sh INPUT.pdf PAGE_NUMin themarkitrightimplementation directory. - [EXTERNAL_DOWNLOADS]: The documentation references a remote resource on a well-known service for demonstration purposes.
- Evidence: Reference to a GitHub Gist (
https://gist.github.com/cdeistopened/fe532c916b97a4e94f66c2014967e972) authored by the skill's creator inLEARNINGS-20260410.md.
Audit Metadata