markdown-converter
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
uvxto execute themarkitdownpackage.markitdownis an official utility provided by Microsoft (a trusted organization) for document-to-markdown conversion. The download and execution of this package from a standard registry is considered safe. - [INDIRECT_PROMPT_INJECTION]: The skill handles the ingestion of external file formats (such as PDF, Word, and Excel) and remote content (YouTube URLs), which creates a potential surface for indirect prompt injection if those files contain malicious instructions meant for an LLM. However, this is the core intended functionality of the tool and is managed by the underlying Microsoft library and the agent's safety layers.
- Ingestion points: Local files (e.g.,
input.pdf,report.docx) and external URLs (YouTube, Azure endpoints). - Boundary markers: None specified in the instructions; formatting is handled by the conversion tool.
- Capability inventory: Reads local files, processes media via OCR/transcription, and outputs Markdown text to the agent.
- Sanitization: Reliability depends on the
markitdownlibrary's extraction logic and the agent's internal filtering.
Audit Metadata