jewel-markdown
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides technical instructions and code snippets for using the Jewel Markdown library. The content is purely educational and architectural, focusing on UI rendering and Markdown processing logic.
- [EXTERNAL_DOWNLOADS]: The skill references source code and documentation hosted on official repositories belonging to well-known and trusted organizations, including JetBrains and Google (Android Studio). These references are documented neutrally as legitimate project resources.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. The skill describes library usage (such as Jsoup for HTML parsing or Coil3 for image loading) through standard programmatic interfaces without invoking unverified remote scripts.
- [PROMPT_INJECTION]: The instructions do not contain any attempts to override agent behavior, bypass safety filters, or extract system prompts. The language used is strictly technical and instructional.
- [DATA_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or unauthorized network operations were found. The skill does not instruct the agent to access or transmit private user data.
- [INDIRECT_PROMPT_INJECTION]: While the skill defines a system for parsing and rendering external Markdown data, it emphasizes safe practices. Specifically, it notes that embedded HTML parsing is disabled by default and provides guidance on using structured converters to map specific HTML tags to native UI components rather than performing arbitrary execution.
Audit Metadata