ai-pdf-builder
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill relies on
npx ai-pdf-builder, which downloads and executes code from the npm registry at runtime. This allows for the execution of arbitrary code from a third-party source not managed by a recognized trusted vendor. - [PRIVILEGE_ESCALATION]: The installation instructions require the user to run commands with root privileges using
sudo, specifically fortlmgr(TeX Live Manager) to install LaTeX collections and forapt-getto install system packages. This grants the skill or its setup process elevated control over the host system. - [EXTERNAL_DOWNLOADS]: The skill fetches content from the npm registry and GitHub repositories associated with 'NextFrontierBuilds' and '@DLhugly'. While npm is a well-known service, the specific package being executed is not from a verified trusted organization.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, potentially untrusted markdown files and prompt strings to generate or enhance documents.
- Ingestion points: Reads content from local markdown files (e.g.,
content.md,draft.md) and accepts arbitrary string prompts for AI generation. - Boundary markers: The instructions lack specific delimiters or instructions to ignore embedded commands within the processed markdown content.
- Capability inventory: The agent is authorized to execute shell commands via
npxand write files to the local system using the-ooutput flag. - Sanitization: While the skill documentation claims to have 'Automatic cleanup of AI-generated content', there is no verifiable evidence of sanitization for the input data provided by users or external files.
Recommendations
- AI detected serious security threats
Audit Metadata