url-to-markdown

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process content from any public web page, which introduces an attack surface for instructions embedded in external data.
  • Ingestion points: The tools strale_url_to_markdown and context_dev_scrape_markdown ingest content from arbitrary URLs provided by the user or found during research.
  • Boundary markers: The instructions do not specify the use of delimiters or clear separation between the agent's instructions and the untrusted content retrieved from the web.
  • Capability inventory: The agent context involves synthesizing findings and citations based on the ingested Markdown content, which could lead the agent to follow instructions hidden in that content.
  • Sanitization: There is no evidence of content sanitization or filtering to remove potential prompt injection payloads from the scraped Markdown.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — url-to-markdown