ClawAudit verdict
minimax-pdf
An HTML-to-PDF production skill using Paged.js with explicit hard constraints against insecure practices (no screenshot hacks, no external charting engines); the dynamic_eval capability reflects the Paged.js rendering pipeline which is documented and expected.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (1)
Uses eval() โ can execute arbitrary code
SKILL.md ยท code ยท eval (
Permissions & capabilities
No declared permissions โ minimal attack surface.
dynamic_eval Is this flag fair?
Thanks โ recorded.