pp-bing-webmaster

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of CLI binaries from the author's GitHub repository (github.com/mvanhorn) and npm package (@mvanhorn/printing-press-library). These sources are associated with the skill vendor.
  • [COMMAND_EXECUTION]: Executes the bing-webmaster-pp-cli tool to interact with the Bing Webmaster API.
  • [INDIRECT_PROMPT_INJECTION]: 1. Ingestion points: Processes local CSV files for GSC reconciliation (--gsc) and reads from stdin for feedback. 2. Boundary markers: No explicit delimiters for external data are specified. 3. Capability inventory: Includes shell command execution and file/webhook writing. 4. Sanitization: No sanitization methods for external inputs are mentioned.
  • [DATA_EXFILTRATION]: Provides a --deliver webhook:<url> feature that allows sending command results to arbitrary external webhooks, which could be misused to exfiltrate data if an agent is misconfigured or coerced.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 08:56 AM
Security Audit — agent-trust-hub — pp-bing-webmaster