markitright

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PDF documents provided by users, which serves as a primary ingestion point for content that could potentially contain adversarial instructions aimed at influencing the agent's behavior during conversion or quality assurance phases.
  • Ingestion points: INPUT.pdf via the markitright CLI and scripts/check_page.sh (referenced in SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters or warnings for the agent to ignore instructions embedded within the processed PDF content.
  • Capability inventory: The skill has the ability to execute shell commands (markitright, scripts/check_page.sh), perform file system writes (markdown output and figures), and make network requests (Gemini API via CLI).
  • Sanitization: No explicit sanitization or filtering of the PDF content is described in the provided instructions.
  • [COMMAND_EXECUTION]: The skill requires the execution of local command-line tools and shell scripts to perform its primary functions.
  • Evidence: Execution of markitright INPUT.pdf -o OUTPUT.md and scripts/check_page.sh INPUT.pdf PAGE_NUM in the markitright implementation directory.
  • [EXTERNAL_DOWNLOADS]: The documentation references a remote resource on a well-known service for demonstration purposes.
  • Evidence: Reference to a GitHub Gist (https://gist.github.com/cdeistopened/fe532c916b97a4e94f66c2014967e972) authored by the skill's creator in LEARNINGS-20260410.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 12:07 PM