pp-printing-press-golden

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a self-learning architecture (documented in SKILL.md and AGENTS.md) where the agent retrieves instructions from a local SQLite database that is populated from external API data or previous interactions. The agent is explicitly directed to follow 'Playbook.notes' and 'Notes' verbatim.
  • Ingestion points: The recall command retrieves content from the local data.db (populated by sync.go from the API).
  • Boundary markers: Absent; instructions emphasize following retrieved notes verbatim without disregard for potentially embedded instructions.
  • Capability inventory: The skill has access to shell execution via the companion CLI binary and network access via the API client.
  • Sanitization: Absent for instructions retrieved during the recall phase.
  • [DATA_EXFILTRATION]: The CLI includes features that facilitate the transfer of data to external endpoints.
  • The --deliver webhook:<url> flag (internal/cli/root.go) allows routing any command results to an arbitrary external URL via HTTP POST.
  • The feedback command (internal/cli/feedback.go) can be configured to automatically ship local feedback logs to a remote endpoint via the PRINTING_PRESS_GOLDEN_FEEDBACK_ENDPOINT environment variable.
  • [EXTERNAL_DOWNLOADS]: The installation instructions (README.md) recommend running npx -y @mvanhorn/printing-press-library, which downloads and executes code from the author's public npm package.
  • [COMMAND_EXECUTION]: The skill's primary function is to drive the printing-press-golden-pp-cli binary using shell tools, and it includes a sql MCP tool (internal/mcp/tools.go) that allows the agent to execute arbitrary read-only SQL queries against the local database.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 11:53 AM
Security Audit — agent-trust-hub — pp-printing-press-golden