ble-desk-lamp

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's prerequisite setup instructions in SKILL.md utilize npx to install the ble-desk-lamp-pp-cli binary from the @mvanhorn/printing-press-library package. This involves downloading and executing installation logic from the vendor's package repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes telemetry and status data from the desk lamp, creating a surface where an adversarial device could potentially provide malformed data to influence the agent's behavior. Ingestion points: Data is ingested through the status and capabilities commands defined in internal/cli/root.go and internal/device/transport.go. Boundary markers: The CLI tool supports structured output via the --json flag to separate data from instructions. Capability inventory: The skill interacts with the local file system to execute the CLI binary and utilizes the tinygo.org/x/bluetooth library for hardware communication. Sanitization: The underlying Go implementation uses defined hex schemas for payloads and structured mapping for telemetry fields in internal/device/spec.go.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:48 AM
Security Audit — agent-trust-hub — ble-desk-lamp