report-to-pdf

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • Local Command Execution: The skill invokes system-level browsers (Chrome/Chromium) and PDF utilities (pdfinfo, pdftotext, pdftoppm) via the CLI to perform conversion and verification. This is the intended purpose of the skill and uses standard system paths.
  • Input Handling and Sanitization: The instructions specifically mandate the removal of internal metadata, runtime fields, and application controls (e.g., share menus, edit buttons) from the final output. This practice helps prevent the accidental exposure of technical details in the generated PDF.
  • Verification Workflow: A structured verification process is included to ensure output integrity, checking for selectable text and visual regressions before finalizing the artifact.
  • Fallback Mechanisms: The skill defines clear logic for handling failures, requiring that any fallback method maintains the original static HTML source as the source of truth rather than reconstructing data from memory.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 02:40 AM
Security Audit — agent-trust-hub — report-to-pdf