pp-agentpool
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the
agentpool-pp-clitool usingnpxfrom the@mvanhornNPM namespace andgo installfrom thegithub.com/mvanhornrepository. These resources are verified as belonging to the skill author. - [COMMAND_EXECUTION]: The skill is designed to execute the
agentpool-pp-clibinary. It includes anexeccommand that permits passing arbitrary arguments to the underlyingagentpoolbinary, which is the intended purpose of this developer tool. - [PROMPT_INJECTION]: The
agentpool-pp-cli skillcommand retrieves agent guidance text that is processed by the AI. This represents an indirect prompt injection surface as the agent is instructed to follow the guidance retrieved from the tool. - Ingestion points: Output from the
agentpool-pp-cli skillcommand inSKILL.md. - Boundary markers: Not explicitly defined in the skill instructions; relies on the agent's internal handling of tool output.
- Capability inventory: The skill has the ability to execute shell commands via the CLI wrapper.
- Sanitization: No sanitization or filtering of the retrieved guidance is described in the skill metadata.
Audit Metadata