ai-pdf-builder

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to execute the ai-pdf-builder package directly from the NPM registry. This is the primary method for running the tool's logic and fetching its dependencies.
  • [COMMAND_EXECUTION]: The skill relies on shell commands for its core functionality, including npx for package execution and which to check for system dependencies like Pandoc. It also provides documentation for system-level package installation via brew and tlmgr.
  • [PROMPT_INJECTION]: The skill features AI-powered content generation and document enhancement, which involves processing external Markdown and PDF files. This presents a potential surface for indirect prompt injection if malicious instructions are embedded within the documents being processed.
  • Ingestion points: Markdown (.md) and PDF files processed via the enhance and summarize commands, as well as raw text prompts.
  • Boundary markers: No specific delimiters or safety instructions are defined in the agent instructions to separate document content from system prompts.
  • Capability inventory: The skill possesses the ability to execute shell commands (via npx), read/write local files, and interact with the Anthropic API (if a key is provided).
  • Sanitization: The documentation explicitly mentions 'Content Sanitization' as a built-in feature to clean up AI-generated output.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — ai-pdf-builder