space-markdown-poster
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: Exposure of author's local file path '/Users/ugreen/Documents/obsidian/attachments' in 'scripts/md2img.py'. This reveals personal directory structure and username information from the development environment.
- [EXTERNAL_DOWNLOADS]: The skill fetches external assets from well-known and legitimate services, including 'img.youtube.com', 'i.ytimg.com', and 'noembed.com', to obtain YouTube thumbnails and metadata for poster generation.
- [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it renders user-provided Markdown content in a headless browser (Playwright) without proper sanitization. * Ingestion points: Markdown content loaded from local files via the --file CLI argument. * Boundary markers: Absent; external content is interpolated directly into HTML templates. * Capability inventory: Headless browser rendering, network access, and file system write operations. * Sanitization: Absent; the implementation uses simple regex for formatting and does not filter potentially malicious HTML tags or scripts that could execute in the browser context.
Audit Metadata