pp-1688

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the 1688-pp-cli tool. It provides instructions to download and install this tool from the vendor's official GitHub repository (github.com/mvanhorn/printing-press-library) and NPM package (@mvanhorn/printing-press-library).
  • [COMMAND_EXECUTION]: The skill's primary function is to execute shell commands using the 1688-pp-cli binary. It passes user-provided arguments and search queries to this binary using the --agent flag for structured output.
  • [DATA_EXFILTRATION]: The skill supports a --deliver webhook:<url> argument, which allows the agent to send the results of a search or analysis to a remote HTTP endpoint. Additionally, it contains a feedback mechanism (1688-pp-cli feedback --send) that can transmit local feedback notes to a remote API endpoint if configured by the user.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from the 1688.com marketplace (search results, supplier details, and product offers). While the data is processed into structured JSON, the skill lacks explicit instructions or boundary markers to prevent the agent from interpreting any natural language instructions that might be present in the product listings.
  • Ingestion points: Search results and product offer details fetched from 1688.com via the search and offers commands.
  • Boundary markers: None present in the instructions.
  • Capability inventory: Execution of the 1688-pp-cli tool, which can perform network requests to 1688.com and user-defined webhooks, and write to local storage (~/.local/share/1688-pp-cli/).
  • Sanitization: The skill uses the --select flag to filter JSON output to specific fields, which reduces the surface area but does not perform content sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 08:42 AM
Security Audit — agent-trust-hub — pp-1688