space-markdown-poster

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: Exposure of author's local file path '/Users/ugreen/Documents/obsidian/attachments' in 'scripts/md2img.py'. This reveals personal directory structure and username information from the development environment.
  • [EXTERNAL_DOWNLOADS]: The skill fetches external assets from well-known and legitimate services, including 'img.youtube.com', 'i.ytimg.com', and 'noembed.com', to obtain YouTube thumbnails and metadata for poster generation.
  • [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it renders user-provided Markdown content in a headless browser (Playwright) without proper sanitization. * Ingestion points: Markdown content loaded from local files via the --file CLI argument. * Boundary markers: Absent; external content is interpolated directly into HTML templates. * Capability inventory: Headless browser rendering, network access, and file system write operations. * Sanitization: Absent; the implementation uses simple regex for formatting and does not filter potentially malicious HTML tags or scripts that could execute in the browser context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 07:05 AM