markdown-to-pdf
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions that explicitly direct the AI agent to ignore platform-specific behaviors, such as 'Ignore Claude-specific mode-switch instructions'. It also mandates a 'Strict execution contract' to ensure its protocol is followed exactly as written, which functions to override default agent operational guidelines.
- [COMMAND_EXECUTION]: The
scripts/lib/chrome-finder.cjsmodule utilizeschild_process.execSyncto run shell commands, includingwhich google-chrome, to locate browser binaries on the host system. - [EXTERNAL_DOWNLOADS]: The skill documentation and
md-to-pdfdependency allow for the automatic download of the Chromium browser if a system-installed version of Chrome or Chromium is not detected. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied Markdown files without utilizing specific boundary markers or sanitization logic, creating a surface where instructions embedded in the processed data could influence agent behavior.
- Ingestion points: Input Markdown files processed in
scripts/convert.cjs. - Boundary markers: None identified in the skill's instructions or logic to delimit external data from agent commands.
- Capability inventory: The skill possesses file system access and network capabilities (via Puppeteer).
- Sanitization: No content validation or instruction filtering is performed on the Markdown data.
Audit Metadata