jupyter-to-marimo
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses the
uvxtool to download and run themarimopackage from the public Python Package Index (PyPI). This is a standard procedure for running CLI utilities without permanent installation. - [COMMAND_EXECUTION]: The agent is instructed to execute shell commands, specifically
marimo convertandmarimo check, to process and validate notebook files on the local file system. - [REMOTE_CODE_EXECUTION]: Code from the
marimopackage is executed at runtime via theuvxrunner to facilitate the file conversion process. - [PROMPT_INJECTION]: The skill processes untrusted Jupyter notebooks, which presents a surface for indirect prompt injection.
- Ingestion points: Input
.ipynbfiles are read and converted as described inSKILL.md. - Boundary markers: The instructions do not define specific delimiters to isolate untrusted notebook content during the review process.
- Capability inventory: The skill includes file system access (read/write) and subprocess execution via the
marimoCLI. - Sanitization: The skill relies on the conversion logic of the
marimolibrary to correctly handle and parse the notebook structure. - [SAFE]: The skill references external documentation for the
wigglystuffextension onkoaning.github.io, which is a well-known and reputable source in the data science community.
Audit Metadata