pp-printing-press-oauth2

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a self-learning loop using a local SQLite database (data.db). The agent is instructed to use recall to fetch previous context and teach to store new information. This creates an attack surface where data processed in one session could influence the agent's behavior in future sessions.
  • Ingestion points: User input processed during command execution and stored via teach (SKILL.md); subsequent retrieval via recall in SKILL.md.
  • Boundary markers: Absent; the skill does not explicitly use delimiters to separate recalled instructions from the current prompt.
  • Capability inventory: The skill has access to the printing-press-oauth2-pp-cli binary, which performs network requests and file system operations. The agent is granted Read Bash tool access.
  • Sanitization: The skill documentation includes a PII rule requiring the agent to strip personal identifiers before storing new mappings, and the CLI binary performs basic scanning for email/phone patterns.
  • [EXTERNAL_DOWNLOADS]: The README and SKILL.md provide instructions to download and install CLI binaries and agent skills from the vendor's infrastructure using npx and GitHub.
  • Sources: @mvanhorn/printing-press-library on NPM and github.com/mvanhorn/printing-press-library for binary releases.
  • Method: Command line installation via npx and manual binary downloads for various platforms (macOS, Linux, Windows).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 11:53 AM
Security Audit — agent-trust-hub — pp-printing-press-oauth2