md-to-pdf-cjk
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
reportlabPython package, which is a widely-used and well-known library for PDF generation. The documentation also provides instructions for installing standard CJK font packages using system package managers. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Markdown data as input to generate PDF files.
- Ingestion points: The
md_pathargument inscripts/md_to_pdf.pyspecifies the source file. - Boundary markers: The script does not use explicit boundary markers to delimit content.
- Capability inventory: The script has file read access (input Markdown) and file write access (output PDF).
- Sanitization: The script performs basic sanitization by escaping HTML-sensitive characters (
&,<,>) in theclean_mdfunction to prevent markup injection in the PDF generator.
Audit Metadata