pp-amc-theatres
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a custom binary named
amc-theatres-pp-cliand an MCP serveramc-theatres-pp-mcpvia the Bash tool to perform theatre and showtime queries.\n- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install external software from sources associated with the author:\n - The
@mvanhorn/printing-press-librarypackage vianpx.\n - The
amc-theatres-pp-cliGo module fromgithub.com/mvanhorn/printing-press-library.\n- [INDIRECT_PROMPT_INJECTION]: The skill implements a self-capturing learning loop (recall,teach,playbook amend) that processes user-controlled input stored in the$USER_QUESTIONenvironment variable. This allows the tool to 'learn' from previous interactions and potentially store malicious instructions if they are included in user queries.\n - Ingestion points: User input provided via the
$USER_QUESTIONenvironment variable to therecall,teach, andplaybook amendcommands inSKILL.md.\n - Boundary markers: The skill documentation notes that standard shell quoting is insufficient to prevent command substitution from user-controlled text.\n
- Capability inventory: The skill possesses the
Bashtool and can execute theamc-theatres-pp-clibinary, which has capabilities for file system access and network delivery via webhooks.\n - Sanitization: The instructions advise the user to strip personally identifiable information (PII) before teaching, but there is no automated sanitization for prompt injection patterns.\n- [DYNAMIC_EXECUTION]: The skill uses a 'playbook' system where sequences of commands are stored in JSON files and replayed by the agent. These playbooks are synthesized and amended based on session journals, which represents a form of dynamic execution guided by processed user data.
Audit Metadata