cloudconvert-converter

Pass

Audited by Gen Agent Trust Hub on Mar 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the official cloudconvert Python SDK, mcp, and python-dotenv from standard registries. These are appropriate and necessary for the skill's documented functionality.
  • [COMMAND_EXECUTION]: Instructions include a shell command (echo) used solely to verify the presence of the required CLOUDCONVERT_API_KEY environment variable. This is a safe and standard environment check.
  • [DATA_EXFILTRATION]: The skill intentionally transmits user-provided files to CloudConvert's official API endpoints for processing. This is the core purpose of the tool and is clearly disclosed in the documentation. CloudConvert is a well-known, legitimate service provider.
  • [SAFE]: No evidence of prompt injection, obfuscation, privilege escalation, or persistence mechanisms was found. The skill's behavior aligns perfectly with its stated purpose and provides clear safety warnings regarding API usage and credit consumption.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 7, 2026, 03:53 AM