skills/hk-hub/agentskills/minimax-pdf/Gen Agent Trust Hub

minimax-pdf

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches and installs necessary dependencies like reportlab, pypdf, and matplotlib via PyPI, and playwright via NPM. It also retrieves fonts from fonts.googleapis.com during the PDF cover rendering process. These sources are well-known and generally trusted for development tools.
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell command execution to manage dependencies and run the document processing pipeline. The make.sh script and several Python scripts (merge.py, render_body.py, etc.) utilize subprocess.check_call to ensure required packages are present, using the --break-system-packages flag to override environment restrictions where necessary.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via the REFORMAT route, which ingests external Markdown, text, or PDF files. These files are parsed and converted into the document's internal JSON structure without explicit sanitization or the use of boundary markers to prevent the agent from potentially interpreting instructions embedded within the source material.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — minimax-pdf