baoyu-markdown-to-html

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided Markdown files which may contain malicious instructions or complex formatting designed to exploit the rendering pipeline.
  • Ingestion points: The main input is the markdown file path provided as a command-line argument to scripts/main.ts.
  • Boundary markers: The instructions do not define clear boundaries or pre-processing steps for the agent to validate the markdown content before conversion.
  • Capability inventory: The skill has capabilities for file reading/writing (fs.readFileSync, fs.writeFileSync), file renaming (fs.renameSync), and subprocess execution for headless Chrome (via the baoyu-chrome-cdp package) to render Mermaid diagrams.
  • Sanitization: The script implements escapeHtmlAttribute for image tag generation, providing some protection against basic injection during final HTML assembly.
  • [COMMAND_EXECUTION]: The skill is designed to be executed via a shell command involving bun or npx to run the main TypeScript script.
  • Evidence: SKILL.md defines the execution pattern: ${BUN_X} {baseDir}/scripts/main.ts <markdown_file> --theme <theme> [--cite].
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:59 AM
Security Audit — agent-trust-hub — baoyu-markdown-to-html