ble-session-appliance
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's setup instructions in
SKILL.mddirect the user to install a CLI tool usingnpx -y @mvanhorn/printing-press-library install ble-session-appliance. This package is a vendor-owned resource managed by the skill's author. - [INDIRECT_PROMPT_INJECTION]: The skill ingests status and telemetry data from external BLE device characteristics (specifically UUID
fd02). This data is stored locally and presented to the agent, creating a surface where a malicious or compromised BLE device could attempt to influence the agent's instructions. - Ingestion points: Telemetry data is captured from characteristic
fd02ininternal/device/store.goand retrieved by the agent via thetelemetry latestcommand. - Boundary markers: The data is returned in structured JSON format, but there are no specific prompt delimiters or instructions to the agent to ignore potential commands embedded within the telemetry values.
- Capability inventory: The skill has the capability to execute commands with physical effects (e.g., the
startcommand on characteristicfd01). - Sanitization: Data is handled using standard Go JSON serialization, which prevents basic injection into the data structure but does not filter the semantic content of the strings for instructions.
- [COMMAND_EXECUTION]: The MCP server (
ble-session-appliance-pp-mcp) is designed to execute theble-session-appliance-pp-clibinary to interact with the device. While this is the intended design for the tool, it involves subprocess execution based on agent-triggered tools.
Audit Metadata