markitdown

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted documents (PDF, Word, HTML, etc.) which are known vectors for indirect prompt injection attacks. The skill includes exceptional documentation on this risk.
  • Ingestion points: The convert_local, convert_stream, convert_uri, and convert_response methods in the MarkItDown API process raw document bytes from potentially untrusted sources.
  • Boundary markers: The skill includes references/security.md, which explicitly instructs agents to label converted Markdown as untrusted source material and separate it from system instructions using clear delimiters.
  • Capability inventory: The skill performs file system operations, network fetches via requests, and calls to remote APIs (Azure/OpenAI). It also interacts with local executables like exiftool.
  • Sanitization: Documentation in references/security.md acknowledges that the converter preserves potentially malicious instructions (e.g., 'ignore previous instructions') and mandates downstream sanitization and independent authorization for actions derived from the content.
  • [EXTERNAL_DOWNLOADS]: The skill guides the user to install official packages including markitdown, markitdown-ocr, markitdown-mcp, and standard SDKs for OpenAI and Azure via the uv package manager. These are well-known and trusted sources.
  • [COMMAND_EXECUTION]: The skill utilizes command-line tools for document conversion (markitdown CLI) and metadata extraction (exiftool). Documentation in references/file_formats.md and references/security.md includes safety requirements for these tools, such as pinning exiftool to version 12.24 or later to avoid known vulnerabilities.
  • [DATA_EXFILTRATION]: The skill discloses that document content, images, and audio may be transmitted to external providers for specialized processing (e.g., Azure Document Intelligence for OCR, Google Web Speech for transcription). These are legitimate, intended functionalities that are clearly disclosed to the user with specific configuration requirements.
  • [DYNAMIC_EXECUTION]: The skill supports an extensible plugin system. Security documentation in references/mcp_and_plugins.md highlights that plugins are disabled by default (enable_plugins=False) and provides a comprehensive 'Plugin Trust Checklist' for users to review third-party code before activation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — markitdown