markdown-to-pdf

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes instructions that explicitly direct the AI agent to ignore platform-specific behaviors, such as 'Ignore Claude-specific mode-switch instructions'. It also mandates a 'Strict execution contract' to ensure its protocol is followed exactly as written, which functions to override default agent operational guidelines.
  • [COMMAND_EXECUTION]: The scripts/lib/chrome-finder.cjs module utilizes child_process.execSync to run shell commands, including which google-chrome, to locate browser binaries on the host system.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and md-to-pdf dependency allow for the automatic download of the Chromium browser if a system-installed version of Chrome or Chromium is not detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied Markdown files without utilizing specific boundary markers or sanitization logic, creating a surface where instructions embedded in the processed data could influence agent behavior.
  • Ingestion points: Input Markdown files processed in scripts/convert.cjs.
  • Boundary markers: None identified in the skill's instructions or logic to delimit external data from agent commands.
  • Capability inventory: The skill possesses file system access and network capabilities (via Puppeteer).
  • Sanitization: No content validation or instruction filtering is performed on the Markdown data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:34 PM
Security Audit — agent-trust-hub — markdown-to-pdf