markdown-new
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: All components of the skill align with its stated purpose of interacting with the markdown.new service, which is a well-known and legitimate utility provided by Cloudflare.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external URLs through the markdown.new API, creating an attack surface where malicious content on target pages could attempt to influence the agent's behavior. This is inherent to the skill's primary function.
- Ingestion points: API responses from https://markdown.new containing converted content from user-specified URLs, processed in
scripts/probe_markdown_new.pyand described inSKILL.md. - Boundary markers: The instructions do not define specific delimiters or "ignore" instructions for the fetched content.
- Capability inventory: The skill uses
urllib.requestfor network communication and can read local files for conversion purposes. - Sanitization: Content is filtered and converted by the third-party markdown.new service into a standardized Markdown format.
- [COMMAND_EXECUTION]: The skill provides utility scripts (
scripts/probe_markdown_new.py,scripts/test_skill.py,scripts/validate.py) for API probing and local validation. These scripts use standard Python libraries, exhibit no malicious behavior, and do not perform any hidden actions. - [EXTERNAL_DOWNLOADS]: The skill's scripts and documentation facilitate interactions with the well-known markdown.new service for fetching and converting web data. These operations are essential to the skill's documented functionality.
Audit Metadata