pp-authentik

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and install administrative tools from the vendor's GitHub repository (github.com/mvanhorn/printing-press-library) using Go and from the @mvanhorn/printing-press-library package on the NPM registry.\n- [REMOTE_CODE_EXECUTION]: The skill facilitates the installation and execution of external binaries (authentik-pp-cli and authentik-pp-mcp) sourced from remote repositories to provide its core functionality.\n- [COMMAND_EXECUTION]: The skill relies on executing shell commands to perform Authentik administration, verify installations, and manage local configurations.\n- [DATA_EXFILTRATION]: The CLI tool supports a --deliver webhook: flag that allows command results to be sent to external webhooks. Additionally, it contains a feedback command that can transmit local data to a remote endpoint if an environment variable is set.\n- [PROMPT_INJECTION]: The skill is exposed to potential indirect prompt injection because it reads and displays data from Authentik (such as user metadata or event logs) that could be controlled by an attacker. This is significant because the agent has the capability to perform sensitive administrative actions based on its interpretation of that data.\n
  • Ingestion points: CLI output from Authentik API resources (SKILL.md), including user lists and event streams.\n
  • Boundary markers: Absent; the skill does not define clear delimiters or instructions to help the agent distinguish between tool output and potential malicious instructions embedded within the data.\n
  • Capability inventory: Full administrative control over the Authentik instance, including the ability to manage tokens, users, and system settings.\n
  • Sanitization: No explicit sanitization or filtering is performed on the data retrieved from the identity provider before it is returned to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 08:36 AM
Security Audit — agent-trust-hub — pp-authentik