office-to-md
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation and utility wrapper for the official Microsoft
markitdowntool. All Python code snippets provided are standard examples of document conversion and file I/O. - [EXTERNAL_DOWNLOADS]: The skill mentions installing the
markitdownpackage viapip install markitdown. This is a well-known, legitimate library from a trusted organization (Microsoft). - [COMMAND_EXECUTION]: Provides command-line examples for using the library (
markitdown document.docx > output.md). These are standard usage patterns for the documented tool. - [DYNAMIC_EXECUTION]: No dynamic code execution (eval/exec) or unsafe deserialization patterns were detected.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes external documents (PDF, Docx, etc.), which is an attack surface, the provided logic does not perform unsafe interpolation into LLM prompts without structure, and it does not grant the agent high-privilege capabilities that would be exploitable via such an injection.
Audit Metadata