Back to skill

Security audit

HTML to PDF

Security checks for vulnerabilities and agentic risk

Overview

This HTML-to-PDF skill does what it claims, but its URL conversion can fetch arbitrary network targets from the user's machine without documented safeguards.

Review before installing. Use this only for trusted local HTML or trusted public URLs, avoid converting internal/private/metadata URLs, choose output paths carefully, and prefer running it in a container or network-restricted environment. Pin Puppeteer with a lockfile and avoid bypassing macOS quarantine unless the browser binary is verified from a trusted source.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/html-to-pdf.js:19
Finding

Unrestricted URL Rendering Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:84
Finding

Unpinned Puppeteer Installation Creates Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
node scripts/html-to-pdf.js input.html output.pdf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
node scripts/html-to-pdf.js input.html output.pdf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
node scripts/html-to-pdf.js input.html output.pdf

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
node scripts/html-to-pdf.js input.html output.pdf

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly supports converting remote URLs, which causes the host running Puppeteer to make outbound network requests to third-party sites. Without a warning, users may unknowingly expose IP address, user agent, timing, and possibly authenticated network reachability or internal URL access patterns, which is a meaningful security and privacy risk in an agent environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup guide advises users to remove the macOS quarantine attribute from a Chrome binary without explaining the trust implications or constraining it to a verified source. Quarantine exists to warn about untrusted downloaded executables, and instructing users to bypass it can normalize running potentially unsafe binaries and reduce host protections.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 64)May include surrounding context.

bash
# Ubuntu/Debian
sudo apt-get install -y libgconf-2-4 \
  libnss3 libxss1 libasound2 libappindicator1 libindicator7 xdg-utils fonts-liberation

# Fedora

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 68)May include surrounding context.

bash
# Ubuntu/Debian
sudo apt-get install -y libgconf-2-4 \
  libnss3 libxss1 libasound2 libappindicator1 libindicator7 xdg-utils fonts-liberation

# Fedora

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The examples show writing a PDF to a user-supplied output path, but the documentation does not warn that running the tool will create or overwrite local files. In an agent workflow, this can lead to unintended file modification, clobbering existing documents, or writing sensitive output to unsafe locations if path handling is not carefully controlled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description states it can convert an HTML file or URL to a PDF and write the result to an output path, which implies both network access for URLs and file creation on disk. The markdown does not include any warning or disclosure about these behaviors' potential privacy or system-impact implications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.