Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a shell script (
scripts/render.sh) to invokepandocfor document rendering. The implementation follows security best practices for shell scripting, such as usingset -euo pipefail, explicit argument parsing, and proper quoting of variables to prevent command injection from malicious filenames or arguments. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user content (Markdown) and processes it through powerful document conversion tools like Pandoc, LaTeX, and WeasyPrint. These tools can sometimes be manipulated via malicious document structures to perform actions such as local file inclusion.
- Ingestion points: User-provided text and data are authored into
content.mdas part of the primary workflow defined inSKILL.md. - Boundary markers: The skill does not employ explicit delimiters or system instructions to ignore embedded commands within the content being processed.
- Capability inventory: The skill has the capability to write files to the local system (
content.md,out.pdf) and execute thepandoccommand with user-controlled parameters. - Sanitization: There is no evidence of input validation, sanitization, or escaping of the Markdown content before it is passed to the rendering engine.
Audit Metadata