pp-cpsc-recalls
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill incorporates an automatic learning loop via the
teachandplaybook amendcommands, which ingest and store session history to generate future playbooks and resource mappings. This architecture presents a surface where untrusted data processed in one session could influence the agent's logic in subsequent sessions. Evidence chain: 1. Ingestion points: Commandsteachandplaybook amendinSKILL.mdprocess user session data. 2. Boundary markers: The documentation instructs the agent to strip personal identifiers before teaching queries. 3. Capability inventory: The skill uses theRead Bashtool to execute thecpsc-recalls-pp-clibinary. 4. Sanitization: Documentation mentions automated scanning for email and phone patterns in taught queries.- [EXTERNAL_DOWNLOADS]: The skill contains instructions to download and install its core command-line components from external sources. It directs the agent to fetch resources from the@mvanhornNPM scope and thegithub.com/mvanhorn/printing-press-libraryrepository using standard package management tools likenpxandgo install.
Audit Metadata