jupyter-to-marimo

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses the uvx tool to download and run the marimo package from the public Python Package Index (PyPI). This is a standard procedure for running CLI utilities without permanent installation.
  • [COMMAND_EXECUTION]: The agent is instructed to execute shell commands, specifically marimo convert and marimo check, to process and validate notebook files on the local file system.
  • [REMOTE_CODE_EXECUTION]: Code from the marimo package is executed at runtime via the uvx runner to facilitate the file conversion process.
  • [PROMPT_INJECTION]: The skill processes untrusted Jupyter notebooks, which presents a surface for indirect prompt injection.
  • Ingestion points: Input .ipynb files are read and converted as described in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters to isolate untrusted notebook content during the review process.
  • Capability inventory: The skill includes file system access (read/write) and subprocess execution via the marimo CLI.
  • Sanitization: The skill relies on the conversion logic of the marimo library to correctly handle and parse the notebook structure.
  • [SAFE]: The skill references external documentation for the wigglystuff extension on koaning.github.io, which is a well-known and reputable source in the data science community.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — jupyter-to-marimo