publication-converter

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted markdown content from user messages or files to generate EPUB publications, creating a surface for indirect prompt injection.\n
  • Ingestion points: The process method in markdown_processor.py accepts raw markdown strings from external sources.\n
  • Boundary markers: The implementation does not utilize specific delimiters or instructions to ignore embedded commands within the processed markdown.\n
  • Capability inventory: The skill utilizes the ebooklib library to perform file system write operations via epub.write_epub in epub_generator.py.\n
  • Sanitization: The skill employs HTML entity escaping in _render_inline and _escape_html within markdown_processor.py to mitigate basic injection into generated XHTML templates.\n- [EXTERNAL_DOWNLOADS]: The skill specifies standard, versioned dependencies for document processing and syntax highlighting.\n
  • Evidence: Pinned versions of ebooklib, markdown2, and Pygments are listed in requirements.txt.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:00 PM
Security Audit — agent-trust-hub — publication-converter