pdf-invoice-generator

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of high-level instructions and examples for generating PDF documents. No malicious code, commands, or security risks were identified.
  • [EXTERNAL_DOWNLOADS]: The instructions suggest using reputable libraries such as Puppeteer, React-PDF, and PDFKit. No commands are provided to download or execute untrusted code.
  • [PROMPT_INJECTION]: The skill describes processing dynamic data (customer info, line items) to generate documents. This represents a potential surface for indirect prompt injection where untrusted data could attempt to influence the agent's behavior during PDF generation.
  • Ingestion points: Dynamic data fields (customer info, line items) and JSON objects mentioned in instructions and examples.
  • Boundary markers: None specified.
  • Capability inventory: No tools or specific scripts are provided; the skill offers conceptual implementation guidance.
  • Sanitization: Not addressed in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 05:33 PM
Security Audit — agent-trust-hub — pdf-invoice-generator