skills/itamaker/skills/webpage-to-pdf/Gen Agent Trust Hub

webpage-to-pdf

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external URLs supplied by the user or found during exploration. An attacker-controlled webpage could attempt to influence the agent's behavior via embedded instructions.
  • Ingestion points: The webpage2pdf/cli.py and webpage2pdf/core.py scripts use driver.get(url) to load external content.
  • Boundary markers: None detected; the skill does not explicitly warn the agent to ignore instructions embedded in the target webpage.
  • Capability inventory: The skill has access to the filesystem (via save_pdf) and network (via Selenium/Chrome).
  • Sanitization: No explicit sanitization or filtering of the webpage content is performed before rendering, although the final output is a rasterized image-based PDF, which prevents direct text-based injection into subsequent agent steps unless OCR is applied.
  • [EXTERNAL_DOWNLOADS]: The skill relies on selenium >= 4.6, which includes Selenium Manager. This utility automatically downloads the matching chromedriver executable from official Google servers when the skill is run.
  • [DYNAMIC_EXECUTION]: In webpage2pdf/core.py, the skill explicitly disables Pillow's protection against decompression bomb attacks by setting Image.MAX_IMAGE_PIXELS = None. While the code comment notes this is intended for handling large screenshots generated by Chrome, it removes a security guardrail that prevents resource exhaustion from malicious or malformed image data.
  • [COMMAND_EXECUTION]: The skill provides a CLI wrapper (webpage2pdf) and instructions for local installation via pip install -e. It uses the Bash tool to execute Chrome and driver-related commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 10:09 AM
Security Audit — agent-trust-hub — webpage-to-pdf