pp-costco
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the
costco-pp-cliandcostco-pp-mcptools vianpxandgo install. These downloads target the author's own GitHub repository (github.com/mvanhorn/printing-press-library) and the official npm registry. These are legitimate installation methods for the tool's intended functionality. - [COMMAND_EXECUTION]: The skill facilitates the execution of local shell commands via the
costco-pp-clibinary to interact with Costco's API and local data. It uses a structured command-line interface with defined flags and subcommands. - [DATA_EXPOSURE]: The skill manages authentication tokens (
idToken) and stores them locally in acredentials.tomlfile within the user's data directory. It explicitly states that no passwords or cookies are stored and provides adoctorcommand for health checks and token management. This is standard practice for CLI tools requiring API authentication. - [REMOTE_CODE_EXECUTION]: While the skill involves downloading and installing a CLI tool, it does not exhibit patterns of piping remote scripts directly into a shell or executing arbitrary code from untrusted external sources at runtime.
Audit Metadata