markitdown
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted documents (PDF, Word, HTML, etc.) which are known vectors for indirect prompt injection attacks. The skill includes exceptional documentation on this risk.
- Ingestion points: The
convert_local,convert_stream,convert_uri, andconvert_responsemethods in the MarkItDown API process raw document bytes from potentially untrusted sources. - Boundary markers: The skill includes
references/security.md, which explicitly instructs agents to label converted Markdown as untrusted source material and separate it from system instructions using clear delimiters. - Capability inventory: The skill performs file system operations, network fetches via
requests, and calls to remote APIs (Azure/OpenAI). It also interacts with local executables likeexiftool. - Sanitization: Documentation in
references/security.mdacknowledges that the converter preserves potentially malicious instructions (e.g., 'ignore previous instructions') and mandates downstream sanitization and independent authorization for actions derived from the content. - [EXTERNAL_DOWNLOADS]: The skill guides the user to install official packages including
markitdown,markitdown-ocr,markitdown-mcp, and standard SDKs for OpenAI and Azure via theuvpackage manager. These are well-known and trusted sources. - [COMMAND_EXECUTION]: The skill utilizes command-line tools for document conversion (
markitdownCLI) and metadata extraction (exiftool). Documentation inreferences/file_formats.mdandreferences/security.mdincludes safety requirements for these tools, such as pinningexiftoolto version 12.24 or later to avoid known vulnerabilities. - [DATA_EXFILTRATION]: The skill discloses that document content, images, and audio may be transmitted to external providers for specialized processing (e.g., Azure Document Intelligence for OCR, Google Web Speech for transcription). These are legitimate, intended functionalities that are clearly disclosed to the user with specific configuration requirements.
- [DYNAMIC_EXECUTION]: The skill supports an extensible plugin system. Security documentation in
references/mcp_and_plugins.mdhighlights that plugins are disabled by default (enable_plugins=False) and provides a comprehensive 'Plugin Trust Checklist' for users to review third-party code before activation.
Audit Metadata