pp-amplitude
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
amplitude-pp-cliandamplitude-pp-mcptools usinggo installfrom the vendor's GitHub repository (github.com/mvanhorn/printing-press-library) andnpxfrom the vendor's NPM scope (@mvanhorn/printing-press-library). These are verified vendor-owned resources. - [COMMAND_EXECUTION]: The skill instructs the agent to execute the
amplitude-pp-clibinary for analytics tasks, including awhichcommand that maps natural language queries to internal tool capabilities. - [DATA_EXFILTRATION]: The CLI tool supports a
--deliver webhook:<url>flag for routing command output to remote endpoints and a feedback mechanism (amplitude-pp-cli feedback) that can be configured to send local notes to a remote server. These are documented features of the integrated CLI. - [CREDENTIALS_UNSAFE]: Authentication is handled via standard practices, guiding users to set an API key in the
AMPLITUDE_USERNAMEenvironment variable or a local configuration file at~/.config/amplitude-read-pp-cli/config.toml.
Audit Metadata