pp-ars-sicilia

Warn

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute a specific binary (ars-sicilia-pp-cli) using shell commands through the Read Bash tool. While scoped to the tool's functionality, this allows for arbitrary argument passing.
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the user or agent to install external software using npx -y @mvanhorn/printing-press-library and go install github.com/mvanhorn/printing-press-library/.... These resources are hosted under the vendor's official namespace.
  • [DATA_EXFILTRATION]: The CLI includes a --deliver webhook:<url> feature that enables the tool to POST its output (which may contain parliamentary records or local processing results) to an arbitrary external network endpoint. This capability can be used to exfiltrate data processed by the agent.
  • [PROMPT_INJECTION]: The skill defines an --agent mode that automatically includes a --yes flag. This configuration instructs the agent to bypass standard interactive confirmation prompts, potentially leading to unintended command execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 09:18 AM
Security Audit — agent-trust-hub — pp-ars-sicilia