batch-convert

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes subprocess.run to call external conversion utilities including pandoc, marp, and soffice (LibreOffice). These calls are implemented using list-based argument passing, which prevents shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The installation instructions reference standard package managers (pip, brew, apt) to fetch well-known libraries and system dependencies. No unverified or suspicious remote code execution patterns were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 07:45 PM
Security Audit — agent-trust-hub — batch-convert