pp-public-param-golden

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill supports a --deliver flag that allows routing command output to a webhook:<url> sink. This feature enables the automated export of data to external endpoints, which could be exploited to exfiltrate sensitive information if an attacker-controlled URL is provided.\n- [REMOTE_CODE_EXECUTION]: The skill's setup instructions direct the user or agent to install the CLI binary using npx -y @mvanhorn/printing-press-library. This executes remote scripts from the author's NPM package to handle the installation.\n- [INDIRECT_PROMPT_INJECTION]: The skill utilizes a local SQLite database to store user queries and command playbooks via a teach mechanism. The recall tool retrieves this data to influence agent behavior. This creates a surface for indirect prompt injection if the local learning store is populated with malicious instructions.\n
  • Ingestion points: User queries and playbook templates are stored in data.db via the teach command.\n
  • Boundary markers: No specific delimiters are used to isolate retrieved playbook content from the agent's instructions.\n
  • Capability inventory: The skill can perform network operations and local file system reads/writes associated with the CLI's functionality.\n
  • Sanitization: The skill implements slot substitution for playbooks but does not perform deep validation of the substituted content.\n- [DYNAMIC_EXECUTION]: The sql tool provides a capability to execute arbitrary SQL queries against the skill's local database. While the implementation includes a security gate to restrict queries to read-only SELECT and WITH statements, it remains a form of dynamic execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 11:53 AM
Security Audit — agent-trust-hub — pp-public-param-golden