comark
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to parse and render markdown content that may come from untrusted sources, including real-time AI generation.
- Ingestion points: Untrusted content enters via the
parseMarkdownfunction and framework-specific rendering components as documented inSKILL.mdandreferences/parsing-ast.md. - Boundary markers: The library provides an
autoClosefeature to manage malformed or incomplete syntax during streaming, though this is primarily for syntax validity rather than security isolation. - Capability inventory: The skill supports rendering custom components with properties and slots, and integrates with plugins like Mermaid and KaTeX. It also supports template binding (
references/rendering-angular.md), which interpolates data into the rendered output. - Sanitization: Parsing is handled by the
markdown-itengine, but the safety of rendered custom components depends on user-defined implementation and framework-level sanitization. - [DYNAMIC_EXECUTION]: The skill uses dynamic component resolution to map markdown tags to executable framework components at runtime.
- Evidence: The Angular renderer (
references/rendering-angular.md) utilizescreateComponentandreflectComponentTypefor dynamic instantiation. The Svelte renderer (references/rendering-svelte.md) demonstrates usingimport.meta.globto dynamically import and resolve components based on computed paths derived from the markdown source.
Audit Metadata