pp-cpsc-recalls

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill incorporates an automatic learning loop via the teach and playbook amend commands, which ingest and store session history to generate future playbooks and resource mappings. This architecture presents a surface where untrusted data processed in one session could influence the agent's logic in subsequent sessions. Evidence chain: 1. Ingestion points: Commands teach and playbook amend in SKILL.md process user session data. 2. Boundary markers: The documentation instructs the agent to strip personal identifiers before teaching queries. 3. Capability inventory: The skill uses the Read Bash tool to execute the cpsc-recalls-pp-cli binary. 4. Sanitization: Documentation mentions automated scanning for email and phone patterns in taught queries.- [EXTERNAL_DOWNLOADS]: The skill contains instructions to download and install its core command-line components from external sources. It directs the agent to fetch resources from the @mvanhorn NPM scope and the github.com/mvanhorn/printing-press-library repository using standard package management tools like npx and go install.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 10:41 PM
Security Audit — agent-trust-hub — pp-cpsc-recalls