markdown-converter

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to parse external documents and web files into Markdown for LLM ingestion, introducing an indirect prompt injection surface if the source data is untrusted.
  • Ingestion points: Handles document and data content via command arguments or stdin streams feeding into uvx markitdown as outlined in SKILL.md.
  • Boundary markers: Absent; the skill does not wrap the converted output in explicit delimiters or issue guardrail instructions to prevent the LLM from executing malicious text contained inside processed files.
  • Capability inventory: Utilizes shell commands (uvx markitdown) to read local filesystem contents and optionally connect to Azure Document Intelligence services.
  • Sanitization: Absent; no parsing logic filters or sanitizes structural scripts or text layout variations before producing the raw Markdown block.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:18 PM
Security Audit — agent-trust-hub — markdown-converter