markdown-to-html
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs on the installation of markdown tools from official package registries.\n
- NPM packages:
marked,dompurify,sanitize-html,js-xss\n - Ruby gems:
jekyll,bundler\n - Go packages:
github.com/gomarkdown/markdown,github.com/gomarkdown/mdtohtml\n- [COMMAND_EXECUTION]: Provides workflows for using command-line tools to process local files.\n - Executables:
marked,pandoc,hugo,jekyll,go,bundle\n- [PROMPT_INJECTION]: The skill processes untrusted Markdown content which creates an indirect prompt injection surface.\n - Ingestion points: Markdown files and strings processed via conversion tools (SKILL.md).\n
- Boundary markers: Lacks specific delimiters or markers for isolating untrusted data within the agent's processing context.\n
- Capability inventory: Shell access for file conversion and local web server management.\n
- Sanitization: Includes explicit recommendations to use sanitization libraries like
DOMPurify,sanitize-html,js-xss, andbluemonday.
Audit Metadata