markdown-to-docx
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONINGPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external Markdown files which serve as an ingestion point for untrusted data. This creates a surface for indirect prompt injection if a processed file contains hidden instructions designed to influence the agent's behavior during or after the conversion process.
- Evidence: The
convertfunction inscripts/lib/converter.cjsreads file content usingfs.readFileSyncand passes it to themarkdown-docxparser without explicit content sanitization or boundary markers. - [METADATA_POISONING]: The
SKILL.mdfile contains contradictory information regarding its requirements. The 'Quick Summary' claims Pandoc is a required dependency, while the 'Features' section and the actual implementation (Node.js scripts) confirm it is a pure JavaScript solution using themarkdown-docxlibrary. This is likely a documentation error or artifact from a template. - Evidence:
SKILL.mdincludes the rule 'Requires pandoc installed on the system' despite thepackage.jsonand scripts relying entirely on Node.js packages. - [PROMPT_INJECTION]: The skill instructions include prescriptive meta-prompts and directives designed to override the agent's default behavior, such as 'Strict execution contract', 'Ignore Claude-specific mode-switch instructions', and mandates for specific confidence thresholds. While intended to ensure task fidelity, these patterns align with behavioral override techniques.
- Evidence: The
SKILL.mdinstructions contain multiple 'SYNC' blocks that define a strict 'Workflow Execution Protocol' and 'Critical Thinking Mindset' that the agent is commanded not to skip.
Audit Metadata