markdown-to-docx

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONINGPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external Markdown files which serve as an ingestion point for untrusted data. This creates a surface for indirect prompt injection if a processed file contains hidden instructions designed to influence the agent's behavior during or after the conversion process.
  • Evidence: The convert function in scripts/lib/converter.cjs reads file content using fs.readFileSync and passes it to the markdown-docx parser without explicit content sanitization or boundary markers.
  • [METADATA_POISONING]: The SKILL.md file contains contradictory information regarding its requirements. The 'Quick Summary' claims Pandoc is a required dependency, while the 'Features' section and the actual implementation (Node.js scripts) confirm it is a pure JavaScript solution using the markdown-docx library. This is likely a documentation error or artifact from a template.
  • Evidence: SKILL.md includes the rule 'Requires pandoc installed on the system' despite the package.json and scripts relying entirely on Node.js packages.
  • [PROMPT_INJECTION]: The skill instructions include prescriptive meta-prompts and directives designed to override the agent's default behavior, such as 'Strict execution contract', 'Ignore Claude-specific mode-switch instructions', and mandates for specific confidence thresholds. While intended to ensure task fidelity, these patterns align with behavioral override techniques.
  • Evidence: The SKILL.md instructions contain multiple 'SYNC' blocks that define a strict 'Workflow Execution Protocol' and 'Critical Thinking Mindset' that the agent is commanded not to skip.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 06:56 AM
Security Audit — agent-trust-hub — markdown-to-docx