printing-press-publish
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local CLI directories to generate pull request descriptions for the public library, which presents a surface for indirect instructions to influence the agent's PR generation.
- Ingestion points: Metadata such as
descriptionandnovel_featuresare read from the.printing-press.jsonmanifest, and prose is extracted from the first few paragraphs of the CLI'sREADME.md. - Boundary markers: The PR description template uses Markdown headers and fenced code blocks to separate user-provided content from the structural elements of the pull request.
- Capability inventory: The skill utilizes
gitand the GitHub CLI (gh) to perform network operations, specifically pushing code to remote branches and creating/editing pull requests. - Sanitization: The skill implements comprehensive sanitization, including a mandatory vendor-prefix secret scan (blocking for tokens like
sk_live_*) and a multi-tiered PII scrubbing process to redact emails and generic bearer tokens before publication. - [EXTERNAL_DOWNLOADS]: The skill references external tools for installation and quality gating.
- It directs the user to install the
cli-printing-pressbinary from the vendor's repository atgithub.com/mvanhorn/cli-printing-press. - It utilizes
govulncheckfrom the officialgolang.orgregistry to verify the security of the CLI being published. - [COMMAND_EXECUTION]: The skill makes extensive use of Bash to manage the publishing workflow.
- It performs repository management (cloning, sparse checkouts, forking, and branch management) and filesystem operations (copying staged packages and renaming files).
- [DYNAMIC_EXECUTION]: The skill dynamically resolves the path to its core binary to maintain environment consistency.
- During the setup phase, the script identifies the absolute path to
cli-printing-pressand enforces its use in all subsequent steps to prevent path hijacking or shadowing by stale global binaries.
Audit Metadata