pp-bing-webmaster
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of CLI binaries from the author's GitHub repository (github.com/mvanhorn) and npm package (@mvanhorn/printing-press-library). These sources are associated with the skill vendor.
- [COMMAND_EXECUTION]: Executes the
bing-webmaster-pp-clitool to interact with the Bing Webmaster API. - [INDIRECT_PROMPT_INJECTION]: 1. Ingestion points: Processes local CSV files for GSC reconciliation (
--gsc) and reads from stdin for feedback. 2. Boundary markers: No explicit delimiters for external data are specified. 3. Capability inventory: Includes shell command execution and file/webhook writing. 4. Sanitization: No sanitization methods for external inputs are mentioned. - [DATA_EXFILTRATION]: Provides a
--deliver webhook:<url>feature that allows sending command results to arbitrary external webhooks, which could be misused to exfiltrate data if an agent is misconfigured or coerced.
Audit Metadata