pp-chrome-history

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the chrome-history-pp-cli binary using npx from the @mvanhorn/printing-press-library npm package and go install from the vendor's GitHub repository.
  • [COMMAND_EXECUTION]: Accesses and processes highly sensitive user information including Chrome browsing history, search terms, and download metadata stored in local SQLite databases.
  • [COMMAND_EXECUTION]: Instructs users to grant 'Full Disk Access' permissions within macOS System Settings to the terminal or agent runtime, enabling the tool to bypass standard file system protections.
  • [COMMAND_EXECUTION]: Utilizes multiple shell commands (e.g., search, sync, sql, archive) to interact with sensitive local data stores, including the creation of local snapshots and archives in ~/.cache/chrome-history/.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 08:29 PM
Security Audit — agent-trust-hub — pp-chrome-history