minimax-pdf
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches and installs necessary dependencies like
reportlab,pypdf, andmatplotlibvia PyPI, andplaywrightvia NPM. It also retrieves fonts fromfonts.googleapis.comduring the PDF cover rendering process. These sources are well-known and generally trusted for development tools. - [COMMAND_EXECUTION]: The skill makes extensive use of shell command execution to manage dependencies and run the document processing pipeline. The
make.shscript and several Python scripts (merge.py,render_body.py, etc.) utilizesubprocess.check_callto ensure required packages are present, using the--break-system-packagesflag to override environment restrictions where necessary. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via the
REFORMATroute, which ingests external Markdown, text, or PDF files. These files are parsed and converted into the document's internal JSON structure without explicit sanitization or the use of boundary markers to prevent the agent from potentially interpreting instructions embedded within the source material.
Audit Metadata