lov-any2pdf
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The documentation in
README.mdandSKILL.mdinstructs the user or agent to runsudo apt installto install necessary font packages on Linux. This involves requesting administrative privileges for system-level modifications.\n- [EXTERNAL_DOWNLOADS]: Themd2pdf.pyscript is designed to download remote assets at runtime. It automatically fetches Twemoji icons from Cloudflare's CDN and retrieves images from arbitrary URLs found within the input Markdown documents.\n- [INDIRECT_PROMPT_INJECTION]: As the skill processes untrusted Markdown data, it is susceptible to indirect prompt injection where malicious content in the document could influence the agent's behavior or trigger unintended network fetches via image tags.\n- [COMMAND_EXECUTION]: The skill's workflow depends on the agent executing shell commands for setting up the environment (usingpipandnpx) and generating the PDF (using the Python script or apandocfallback).
Audit Metadata