md-to-pdf-cjk

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the reportlab Python package, which is a widely-used and well-known library for PDF generation. The documentation also provides instructions for installing standard CJK font packages using system package managers.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Markdown data as input to generate PDF files.
  • Ingestion points: The md_path argument in scripts/md_to_pdf.py specifies the source file.
  • Boundary markers: The script does not use explicit boundary markers to delimit content.
  • Capability inventory: The script has file read access (input Markdown) and file write access (output PDF).
  • Sanitization: The script performs basic sanitization by escaping HTML-sensitive characters (&, <, >) in the clean_md function to prevent markup injection in the PDF generator.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — md-to-pdf-cjk