pp-fellow-stagg-ekg

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the fellow-stagg-ekg-pp-cli utility using npx from the @mvanhorn/printing-press-library package and go install from the vendor's GitHub repository (github.com/mvanhorn/printing-press-library). These resources originate from the identified vendor's infrastructure and are consistent with the skill's stated purpose.
  • [COMMAND_EXECUTION]: The skill utilizes a custom CLI binary to execute commands on the local system. These commands are intended to communicate with the kettle's local HTTP API to manage settings, temperature, and hardware states (e.g., dial, button, buzzer).
  • [PROMPT_INJECTION]: The skill processes data retrieved from the kettle (such as firmware info and status). This constitutes an ingestion point for external data that could theoretically be used for indirect prompt injection, although the impact is limited to the specialized kettle control context.
  • Ingestion points: status, state, settings, and info commands that read from the kettle's HTTP interface.
  • Boundary markers: No specific delimiters or safety warnings are present in the instructions to separate device data from agent instructions.
  • Capability inventory: The skill is scoped to the fellow-stagg-ekg-pp-cli binary and environment variable configuration.
  • Sanitization: The instructions do not specify sanitization or validation of the device's responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 10:59 PM
Security Audit — agent-trust-hub — pp-fellow-stagg-ekg