skills/lucas-ataides/skills/pdf/Gen Agent Trust Hub

pdf

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a shell script (scripts/render.sh) to invoke pandoc for document rendering. The implementation follows security best practices for shell scripting, such as using set -euo pipefail, explicit argument parsing, and proper quoting of variables to prevent command injection from malicious filenames or arguments.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user content (Markdown) and processes it through powerful document conversion tools like Pandoc, LaTeX, and WeasyPrint. These tools can sometimes be manipulated via malicious document structures to perform actions such as local file inclusion.
  • Ingestion points: User-provided text and data are authored into content.md as part of the primary workflow defined in SKILL.md.
  • Boundary markers: The skill does not employ explicit delimiters or system instructions to ignore embedded commands within the content being processed.
  • Capability inventory: The skill has the capability to write files to the local system (content.md, out.pdf) and execute the pandoc command with user-controlled parameters.
  • Sanitization: There is no evidence of input validation, sanitization, or escaping of the Markdown content before it is passed to the rendering engine.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:15 PM
Security Audit — agent-trust-hub — pdf