batch-convert
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
subprocess.runto call external conversion utilities includingpandoc,marp, andsoffice(LibreOffice). These calls are implemented using list-based argument passing, which prevents shell injection vulnerabilities. - [EXTERNAL_DOWNLOADS]: The installation instructions reference standard package managers (pip, brew, apt) to fetch well-known libraries and system dependencies. No unverified or suspicious remote code execution patterns were found.
Audit Metadata