skills/mblode/agent-skills/save-md/Gen Agent Trust Hub

save-md

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes several standard command-line tools such as curl, yt-dlp, pandoc, and soffice for content retrieval and conversion. The instructions emphasize proper parameter handling (e.g., -L for redirects) and include a specific evaluation test in evals/evals.json to ensure the agent does not perform shell expansion on untrusted content like $HOME during the saving process.
  • [INDIRECT_PROMPT_INJECTION]: As the skill's primary function is to ingest data from external sources, it is exposed to indirect prompt injection. However, it implements a robust mitigation strategy:
  • Ingestion points: Data is ingested from various sources including public URLs, YouTube transcripts, Google Docs, and PDFs as described in SKILL.md and references/source-endpoints.md.
  • Boundary markers: Extracted content is encapsulated within a .md file using YAML frontmatter delimiters as defined in SKILL.md.
  • Capability inventory: The skill uses curl, yt-dlp, pandoc, soffice, unzip, and gh api to process and store data.
  • Sanitization: Security is primarily managed through evaluation tests in evals/evals.json which assert that literal text (e.g., shell variables and backticks) is preserved without expansion, and instructions to perform direct byte extraction rather than summarization.
  • [DATA_EXFILTRATION]: The skill provides an opt-in path for using Firecrawl, a third-party scraping service. The documentation in references/source-endpoints.md proactively addresses the privacy implications, stating that these services see every URL sent to them and advising the agent to never send private, internal, or signed URLs without explicit user consent.
  • [EXTERNAL_DOWNLOADS]: Fetches data from well-known and trusted services including GitHub, Google Drive/Docs, arXiv, Wikipedia, and YouTube. These interactions are documented as core functionality of the skill, and the skill specifies the use of official or common endpoints for clean data retrieval.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 11:01 PM
Security Audit — agent-trust-hub — save-md