pp-printing-press-rich

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The installation instructions utilize npx to download and execute the @mvanhorn/printing-press-library package from the NPM registry, which is the vendor's documented distribution method. \n- [COMMAND_EXECUTION]: The skill implements a sql tool for local data analysis. It includes a security validator (validateReadOnlyQuery) that restricts input to single SELECT or WITH statements and uses read-only database connections to prevent unauthorized modifications. \n- [COMMAND_EXECUTION]: All CLI commands from the printing-press-rich-pp-cli binary are mirrored as agent tools using cobratree.RegisterAll, allowing the agent to perform documented CLI operations. \n- [DATA_EXPOSURE]: The agent-context command and context tool expose resolved filesystem paths for the CLI's configuration and data directories to provide environment awareness to the AI agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:41 AM
Security Audit — agent-trust-hub — pp-printing-press-rich