printing-press-polish

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill uses go install and go run to fetch and execute tools (cli-printing-press and gosec). These are recognized as coming from the vendor (mvanhorn) or well-known security projects (securego), which are treated as safe sources.
  • [COMMAND_EXECUTION]: The skill executes various Bash commands for file system operations, diagnostics, and building Go binaries. These operations are core to the skill's purpose and are performed within a forked context to limit side effects.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project data (README, manifests, research files) and user-supplied scope strings ingested via the 'args' variable. While explicit sanitization is not implemented, these ingestion points are required for the skill's functionality. The skill's capabilities include file editing and shell execution, creating a standard development tool surface area.
  • [DATA_EXFILTRATION]: The skill includes a 'Publish Offer' for interaction with the public printing-press-library repository. This action is explicitly gated by user confirmation and follows transparency guidelines for cross-repository operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:00 PM
Security Audit — agent-trust-hub — printing-press-polish