pp-bookmakersreview

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to download and install executable code from external sources. Specifically, it uses npx to install @mvanhorn/printing-press-library and go install to fetch the CLI from a GitHub repository. These resources are owned by the verified vendor for this skill.
  • [COMMAND_EXECUTION]: The skill frequently executes the bookmakersreview-pp-cli binary with arguments derived from user input, including natural language strings passed to the which, recall, and teach commands.
  • [DATA_EXFILTRATION]: The CLI includes a built-in --deliver webhook:<url> feature. This allows the output of any command—including potentially sensitive local betting records or raw database queries—to be transmitted to an arbitrary external URL provided by the user or an attacker.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its processing of external, unauthenticated data.
  • Ingestion points: Untrusted data enters the agent context via the BookmakersReview GraphQL API (odds-v2 service) and through natural language queries processed by the recall and teach commands.
  • Boundary markers: There are no explicit boundary markers or instructions to the model to ignore embedded commands within the ingested data.
  • Capability inventory: The CLI possesses powerful capabilities, including writing to arbitrary file paths (--deliver file:) and making outbound network requests (--deliver webhook:).
  • Sanitization: The skill does not demonstrate sanitization or validation of the content retrieved from external APIs before it is used to influence agent behavior.
  • [DYNAMIC_EXECUTION]: The skill implements a sophisticated 'learning loop' where command sequences are recorded and stored as 'playbooks'.
  • Evidence: The teach command journalizes sessions to create playbook_candidate entries in a local SQLite database, and the recall command executes these stored steps using dynamic slot substitution for entities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 03:45 AM
Security Audit — agent-trust-hub — pp-bookmakersreview