publication-converter
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted markdown content from user messages or files to generate EPUB publications, creating a surface for indirect prompt injection.\n
- Ingestion points: The
processmethod inmarkdown_processor.pyaccepts raw markdown strings from external sources.\n - Boundary markers: The implementation does not utilize specific delimiters or instructions to ignore embedded commands within the processed markdown.\n
- Capability inventory: The skill utilizes the
ebookliblibrary to perform file system write operations viaepub.write_epubinepub_generator.py.\n - Sanitization: The skill employs HTML entity escaping in
_render_inlineand_escape_htmlwithinmarkdown_processor.pyto mitigate basic injection into generated XHTML templates.\n- [EXTERNAL_DOWNLOADS]: The skill specifies standard, versioned dependencies for document processing and syntax highlighting.\n - Evidence: Pinned versions of
ebooklib,markdown2, andPygmentsare listed inrequirements.txt.
Audit Metadata