pp-costco

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the costco-pp-cli and costco-pp-mcp tools via npx and go install. These downloads target the author's own GitHub repository (github.com/mvanhorn/printing-press-library) and the official npm registry. These are legitimate installation methods for the tool's intended functionality.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of local shell commands via the costco-pp-cli binary to interact with Costco's API and local data. It uses a structured command-line interface with defined flags and subcommands.
  • [DATA_EXPOSURE]: The skill manages authentication tokens (idToken) and stores them locally in a credentials.toml file within the user's data directory. It explicitly states that no passwords or cookies are stored and provides a doctor command for health checks and token management. This is standard practice for CLI tools requiring API authentication.
  • [REMOTE_CODE_EXECUTION]: While the skill involves downloading and installing a CLI tool, it does not exhibit patterns of piping remote scripts directly into a shell or executing arbitrary code from untrusted external sources at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:24 PM
Security Audit — agent-trust-hub — pp-costco