ai-pdf-builder

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill relies on npx ai-pdf-builder, which downloads and executes code from the npm registry at runtime. This allows for the execution of arbitrary code from a third-party source not managed by a recognized trusted vendor.
  • [PRIVILEGE_ESCALATION]: The installation instructions require the user to run commands with root privileges using sudo, specifically for tlmgr (TeX Live Manager) to install LaTeX collections and for apt-get to install system packages. This grants the skill or its setup process elevated control over the host system.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from the npm registry and GitHub repositories associated with 'NextFrontierBuilds' and '@DLhugly'. While npm is a well-known service, the specific package being executed is not from a verified trusted organization.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, potentially untrusted markdown files and prompt strings to generate or enhance documents.
  • Ingestion points: Reads content from local markdown files (e.g., content.md, draft.md) and accepts arbitrary string prompts for AI generation.
  • Boundary markers: The instructions lack specific delimiters or instructions to ignore embedded commands within the processed markdown content.
  • Capability inventory: The agent is authorized to execute shell commands via npx and write files to the local system using the -o output flag.
  • Sanitization: While the skill documentation claims to have 'Automatic cleanup of AI-generated content', there is no verifiable evidence of sanitization for the input data provided by users or external files.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — ai-pdf-builder