baoyu-url-to-markdown

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses the Chrome DevTools Protocol (CDP) Runtime.evaluate method to execute static JavaScript snippets within the controlled browser instance for data extraction, Shadow DOM materialization, and page interaction across various adapters (e.g., scripts/lib/browser/session.ts, scripts/lib/browser/page-snapshot.ts).
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to https://defuddle.md to fetch markdown content as a fallback for generic web pages (scripts/lib/extract/html-to-markdown.ts). It also downloads media assets (images and videos) from remote URLs discovered within processed pages using the standard fetch API (scripts/lib/media/default-downloader.ts).
  • [COMMAND_EXECUTION]: The skill's setup and execution involve standard command-line operations, including dependency installation via bun install and execution of the extraction logic via bun ./lib/cli.ts (SKILL.md, scripts/baoyu-fetch).
  • [PERSISTENCE]: The skill implements a legitimate session persistence feature for X (Twitter) by exporting and restoring specific authentication cookies (auth_token, ct0) to a local file named x-session-cookies.json within the Chrome profile directory, allowing users to maintain logged-in states between runs (scripts/lib/browser/cookie-sidecar.ts).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted HTML content from arbitrary user-provided URLs.
  • Ingestion points: Webpage content is ingested via BrowserSession.getHTML() and various Runtime.evaluate calls across multiple site-specific adapters.
  • Boundary markers: No specific boundary markers or instructions are used to delimit the external content within the agent's context.
  • Capability inventory: The skill can write files to the local file system (writeFile, mkdir in scripts/lib/commands/convert.ts) and perform network operations via the controlled browser and fetch API.
  • Sanitization: A dedicated cleanHtml utility (scripts/lib/extract/html-cleaner.ts) is used to strip scripts, styles, advertisements, and other potentially problematic elements before conversion to markdown.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:16 AM
Security Audit — agent-trust-hub — baoyu-url-to-markdown