pp-company-goat
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads and installs software from the vendor's GitHub repository and NPM organization (
@mvanhorn/printing-press-library). - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from multiple external sources.
- Ingestion points: Processes data from Hacker News (mentions and launches), SEC Form D filings, GitHub organization metadata, and YC directory entries.
- Boundary markers: No specific delimiters or instructions to ignore embedded directives are provided in the prompt logic.
- Capability inventory: The tool can perform shell command execution (via
Read Bash), file writes (using--deliver file:<path>), and network POST requests (using--deliver webhook:<url>). - Sanitization: No sanitization or validation of the ingested external content is mentioned before it is processed by the agent.
- [DATA_EXFILTRATION]: The tool includes a
--deliverparameter that can send research results to external endpoints via webhooks (webhook:<url>), which could be misused to exfiltrate data. - [COMMAND_EXECUTION]: The skill executes the
company-goat-pp-clibinary using arguments derived from user input.
Audit Metadata