pp-1688
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
1688-pp-clitool. It provides instructions to download and install this tool from the vendor's official GitHub repository (github.com/mvanhorn/printing-press-library) and NPM package (@mvanhorn/printing-press-library). - [COMMAND_EXECUTION]: The skill's primary function is to execute shell commands using the
1688-pp-clibinary. It passes user-provided arguments and search queries to this binary using the--agentflag for structured output. - [DATA_EXFILTRATION]: The skill supports a
--deliver webhook:<url>argument, which allows the agent to send the results of a search or analysis to a remote HTTP endpoint. Additionally, it contains a feedback mechanism (1688-pp-cli feedback --send) that can transmit local feedback notes to a remote API endpoint if configured by the user. - [PROMPT_INJECTION]: The skill ingests untrusted data from the 1688.com marketplace (search results, supplier details, and product offers). While the data is processed into structured JSON, the skill lacks explicit instructions or boundary markers to prevent the agent from interpreting any natural language instructions that might be present in the product listings.
- Ingestion points: Search results and product offer details fetched from 1688.com via the
searchandofferscommands. - Boundary markers: None present in the instructions.
- Capability inventory: Execution of the
1688-pp-clitool, which can perform network requests to 1688.com and user-defined webhooks, and write to local storage (~/.local/share/1688-pp-cli/). - Sanitization: The skill uses the
--selectflag to filter JSON output to specific fields, which reduces the surface area but does not perform content sanitization.
Audit Metadata