pp-printing-press-oauth2
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a self-learning loop using a local SQLite database (
data.db). The agent is instructed to userecallto fetch previous context andteachto store new information. This creates an attack surface where data processed in one session could influence the agent's behavior in future sessions. - Ingestion points: User input processed during command execution and stored via
teach(SKILL.md); subsequent retrieval viarecallinSKILL.md. - Boundary markers: Absent; the skill does not explicitly use delimiters to separate recalled instructions from the current prompt.
- Capability inventory: The skill has access to the
printing-press-oauth2-pp-clibinary, which performs network requests and file system operations. The agent is grantedRead Bashtool access. - Sanitization: The skill documentation includes a PII rule requiring the agent to strip personal identifiers before storing new mappings, and the CLI binary performs basic scanning for email/phone patterns.
- [EXTERNAL_DOWNLOADS]: The README and SKILL.md provide instructions to download and install CLI binaries and agent skills from the vendor's infrastructure using
npxand GitHub. - Sources:
@mvanhorn/printing-press-libraryon NPM andgithub.com/mvanhorn/printing-press-libraryfor binary releases. - Method: Command line installation via
npxand manual binary downloads for various platforms (macOS, Linux, Windows).
Audit Metadata