skills/garrytan/gstack/make-pdf/Gen Agent Trust Hub

make-pdf

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill maintains an "offline posture" by blocking remote image fetches in markdown files by default, protecting users from tracking pixels. Telemetry data is logged only to a local directory (~/.gstack/analytics/).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted markdown data but implements comprehensive defenses. It sanitizes HTML to remove dangerous tags (like and ) and prevents the inclusion of files outside the document's directory. It also mandates validation of any instructions received from internal tools using a session ID.
  • [DYNAMIC_EXECUTION]: Rendering of diagrams (Mermaid, Excalidraw) and oversized images is performed using a browser-based rendering engine in a controlled environment. This is a core part of the skill's functionality and is implemented with appropriate security boundaries.
  • [COMMAND_EXECUTION]: The skill relies on local binaries and system tools (like pdftotext or browser engines) to perform its tasks. The execution is scoped to the skill's specific purpose of document generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 02:36 PM
Security Audit — agent-trust-hub — make-pdf