pp-company-goat

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and installs software from the vendor's GitHub repository and NPM organization (@mvanhorn/printing-press-library).
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from multiple external sources.
  • Ingestion points: Processes data from Hacker News (mentions and launches), SEC Form D filings, GitHub organization metadata, and YC directory entries.
  • Boundary markers: No specific delimiters or instructions to ignore embedded directives are provided in the prompt logic.
  • Capability inventory: The tool can perform shell command execution (via Read Bash), file writes (using --deliver file:<path>), and network POST requests (using --deliver webhook:<url>).
  • Sanitization: No sanitization or validation of the ingested external content is mentioned before it is processed by the agent.
  • [DATA_EXFILTRATION]: The tool includes a --deliver parameter that can send research results to external endpoints via webhooks (webhook:<url>), which could be misused to exfiltrate data.
  • [COMMAND_EXECUTION]: The skill executes the company-goat-pp-cli binary using arguments derived from user input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:14 PM
Security Audit — agent-trust-hub — pp-company-goat