markdown-to-pdf

Warn

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted Markdown data through the --input parameter, creating a vulnerability surface if the agent is directed to process external or attacker-controlled files.
  • Ingestion points: The file scripts/lib/converter.cjs reads Markdown content using the loadMarkdown function.
  • Boundary markers: There are no delimiters or specific instructions to the underlying engine to ignore embedded commands or malicious HTML/JS within the input content.
  • Capability inventory: The skill uses md-to-pdf, which leverages a headless Chromium browser via Puppeteer to render the final document.
  • Sanitization: The skill does not perform sanitization of HTML tags or JavaScript blocks within the Markdown source. This allows embedded scripts or tags (like <iframe> or <script>) to be executed or interpreted by the rendering engine.
  • [DYNAMIC_EXECUTION]: The skill converts content by rendering it in a headless Chromium instance. Maliciously crafted Markdown can exploit the browser's rendering capabilities to perform Server-Side Request Forgery (SSRF) or Local File Inclusion (LFI). Furthermore, scripts/lib/chrome-finder.cjs explicitly adds the --no-sandbox and --disable-setuid-sandbox flags to the browser launch arguments when running on Windows or in environments where CI or DOCKER variables are set, which significantly reduces the browser's isolation and security posture.
  • [COMMAND_EXECUTION]: The helper utility scripts/lib/chrome-finder.cjs uses execSync to run shell commands (e.g., which google-chrome) to locate system-installed browsers. While the command string is static and does not incorporate user input, it represents an intentional use of shell execution.
  • [EXTERNAL_DOWNLOADS]: As noted in SKILL.md, the skill may trigger a download of the Chromium browser (~150MB) during its first run if a compatible system-wide installation of Chrome or Chromium is not found. This download is handled automatically by the puppeteer dependency.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 27, 2026, 02:48 AM
Security Audit — agent-trust-hub — markdown-to-pdf