baoyu-markdown-to-html
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided Markdown files which may contain malicious instructions or complex formatting designed to exploit the rendering pipeline.
- Ingestion points: The main input is the markdown file path provided as a command-line argument to
scripts/main.ts. - Boundary markers: The instructions do not define clear boundaries or pre-processing steps for the agent to validate the markdown content before conversion.
- Capability inventory: The skill has capabilities for file reading/writing (
fs.readFileSync,fs.writeFileSync), file renaming (fs.renameSync), and subprocess execution for headless Chrome (via thebaoyu-chrome-cdppackage) to render Mermaid diagrams. - Sanitization: The script implements
escapeHtmlAttributefor image tag generation, providing some protection against basic injection during final HTML assembly. - [COMMAND_EXECUTION]: The skill is designed to be executed via a shell command involving
bunornpxto run the main TypeScript script. - Evidence:
SKILL.mddefines the execution pattern:${BUN_X} {baseDir}/scripts/main.ts <markdown_file> --theme <theme> [--cite].
Audit Metadata