skills/aeondave/malskill/pinggy/Gen Agent Trust Hub

pinggy

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends installing the Pinggy CLI and SDK from official package registries (NPM and PyPI) for local tunnel management.
  • [COMMAND_EXECUTION]: Provides numerous OpenSSH and Docker command examples for establishing remote port forwarding and tunneling services.
  • [DATA_EXFILTRATION]: Documents the core functionality of exposing local ports to the internet. It includes built-in security features such as Basic and Bearer authentication, CIDR-based IP allowlists, and specific guidance on using TLS tunnels to ensure privacy.
  • [PRIVILEGE_ESCALATION]: Includes a Docker command using --net=host to expose local services from within a container environment, bypassing standard network isolation.
  • [INDIRECT_PROMPT_INJECTION]: Identifies webhook capture and API testing as primary use cases (ingestion points in SKILL.md and usage-matrix.md). The skill includes a 'Scope Guard' section with boundary instructions to limit exposure. The underlying capabilities include subprocess execution via SSH, Docker, and the Pinggy CLI. While explicit sanitization is not detailed, the skill provides authentication and IP allowlisting tools to control access to the ingestion points.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — pinggy