convert

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external sources into the agent's context.
  • Ingestion points: The $ARGUMENTS variable in SKILL.md allows the agent to process arbitrary URLs (including data: URIs) and local file paths.
  • Boundary markers: The instructions do not specify any delimiters or safety warnings to ensure the agent treats the converted output as passive data rather than active instructions.
  • Capability inventory: The skill leverages the convert_to_markdown tool to fetch and interpret data from the specified URIs.
  • Sanitization: No validation or filtering is performed on the content returned by the conversion tool before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:46 PM