cloudconvert-converter
Pass
Audited by Gen Agent Trust Hub on Mar 7, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the official
cloudconvertPython SDK,mcp, andpython-dotenvfrom standard registries. These are appropriate and necessary for the skill's documented functionality. - [COMMAND_EXECUTION]: Instructions include a shell command (
echo) used solely to verify the presence of the requiredCLOUDCONVERT_API_KEYenvironment variable. This is a safe and standard environment check. - [DATA_EXFILTRATION]: The skill intentionally transmits user-provided files to CloudConvert's official API endpoints for processing. This is the core purpose of the tool and is clearly disclosed in the documentation. CloudConvert is a well-known, legitimate service provider.
- [SAFE]: No evidence of prompt injection, obfuscation, privilege escalation, or persistence mechanisms was found. The skill's behavior aligns perfectly with its stated purpose and provides clear safety warnings regarding API usage and credit consumption.
Audit Metadata