markdown-converter
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to parse external documents and web files into Markdown for LLM ingestion, introducing an indirect prompt injection surface if the source data is untrusted.
- Ingestion points: Handles document and data content via command arguments or stdin streams feeding into
uvx markitdownas outlined inSKILL.md. - Boundary markers: Absent; the skill does not wrap the converted output in explicit delimiters or issue guardrail instructions to prevent the LLM from executing malicious text contained inside processed files.
- Capability inventory: Utilizes shell commands (
uvx markitdown) to read local filesystem contents and optionally connect to Azure Document Intelligence services. - Sanitization: Absent; no parsing logic filters or sanitizes structural scripts or text layout variations before producing the raw Markdown block.
Audit Metadata