paged-reports
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to locate and execute a local PDF generation binary (pdf) from the chrome-driver plugin cache.
- [EXTERNAL_DOWNLOADS]: HTML templates reference and load assets from well-known services, specifically the paged.js polyfill from unpkg.com and typography from Google Fonts.
- [PROMPT_INJECTION]: The skill represents an indirect prompt injection surface by processing external markdown content for rendering. Ingestion points: Markdown source file content. Boundary markers: None identified. Capability inventory: Local command execution for document rendering. Sanitization: No explicit content filtering is documented.
Audit Metadata