webpage-to-pdf
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external URLs supplied by the user or found during exploration. An attacker-controlled webpage could attempt to influence the agent's behavior via embedded instructions.
- Ingestion points: The
webpage2pdf/cli.pyandwebpage2pdf/core.pyscripts usedriver.get(url)to load external content. - Boundary markers: None detected; the skill does not explicitly warn the agent to ignore instructions embedded in the target webpage.
- Capability inventory: The skill has access to the filesystem (via
save_pdf) and network (via Selenium/Chrome). - Sanitization: No explicit sanitization or filtering of the webpage content is performed before rendering, although the final output is a rasterized image-based PDF, which prevents direct text-based injection into subsequent agent steps unless OCR is applied.
- [EXTERNAL_DOWNLOADS]: The skill relies on
selenium >= 4.6, which includes Selenium Manager. This utility automatically downloads the matchingchromedriverexecutable from official Google servers when the skill is run. - [DYNAMIC_EXECUTION]: In
webpage2pdf/core.py, the skill explicitly disables Pillow's protection against decompression bomb attacks by settingImage.MAX_IMAGE_PIXELS = None. While the code comment notes this is intended for handling large screenshots generated by Chrome, it removes a security guardrail that prevents resource exhaustion from malicious or malformed image data. - [COMMAND_EXECUTION]: The skill provides a CLI wrapper (
webpage2pdf) and instructions for local installation viapip install -e. It uses theBashtool to execute Chrome and driver-related commands.
Audit Metadata