convert
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external sources into the agent's context.
- Ingestion points: The
$ARGUMENTSvariable inSKILL.mdallows the agent to process arbitrary URLs (includingdata:URIs) and local file paths. - Boundary markers: The instructions do not specify any delimiters or safety warnings to ensure the agent treats the converted output as passive data rather than active instructions.
- Capability inventory: The skill leverages the
convert_to_markdowntool to fetch and interpret data from the specified URIs. - Sanitization: No validation or filtering is performed on the content returned by the conversion tool before it is presented to the agent.
Audit Metadata