ai-pdf-builder
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npxto execute theai-pdf-builderpackage directly from the NPM registry. This is the primary method for running the tool's logic and fetching its dependencies. - [COMMAND_EXECUTION]: The skill relies on shell commands for its core functionality, including
npxfor package execution andwhichto check for system dependencies like Pandoc. It also provides documentation for system-level package installation viabrewandtlmgr. - [PROMPT_INJECTION]: The skill features AI-powered content generation and document enhancement, which involves processing external Markdown and PDF files. This presents a potential surface for indirect prompt injection if malicious instructions are embedded within the documents being processed.
- Ingestion points: Markdown (
.md) and PDF files processed via theenhanceandsummarizecommands, as well as raw text prompts. - Boundary markers: No specific delimiters or safety instructions are defined in the agent instructions to separate document content from system prompts.
- Capability inventory: The skill possesses the ability to execute shell commands (via
npx), read/write local files, and interact with the Anthropic API (if a key is provided). - Sanitization: The documentation explicitly mentions 'Content Sanitization' as a built-in feature to clean up AI-generated output.
Audit Metadata