pp-public-param-golden
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill supports a
--deliverflag that allows routing command output to awebhook:<url>sink. This feature enables the automated export of data to external endpoints, which could be exploited to exfiltrate sensitive information if an attacker-controlled URL is provided.\n- [REMOTE_CODE_EXECUTION]: The skill's setup instructions direct the user or agent to install the CLI binary usingnpx -y @mvanhorn/printing-press-library. This executes remote scripts from the author's NPM package to handle the installation.\n- [INDIRECT_PROMPT_INJECTION]: The skill utilizes a local SQLite database to store user queries and command playbooks via a teach mechanism. Therecalltool retrieves this data to influence agent behavior. This creates a surface for indirect prompt injection if the local learning store is populated with malicious instructions.\n - Ingestion points: User queries and playbook templates are stored in
data.dbvia theteachcommand.\n - Boundary markers: No specific delimiters are used to isolate retrieved playbook content from the agent's instructions.\n
- Capability inventory: The skill can perform network operations and local file system reads/writes associated with the CLI's functionality.\n
- Sanitization: The skill implements slot substitution for playbooks but does not perform deep validation of the substituted content.\n- [DYNAMIC_EXECUTION]: The
sqltool provides a capability to execute arbitrary SQL queries against the skill's local database. While the implementation includes a security gate to restrict queries to read-onlySELECTandWITHstatements, it remains a form of dynamic execution.
Audit Metadata