pp-flight-goat

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (flight fares, route info, WiFi speeds) from various third-party providers.
  • Ingestion points: Data returned from search and status commands including flights, dates, explore, soar, award, and wifi (SKILL.md).
  • Boundary markers: The instructions do not define explicit delimiters or 'ignore embedded instructions' warnings for processing the results from these tools.
  • Capability inventory: The skill has the capability to execute shell commands, write to a local SQLite store (teach), and send data to external URLs (webhook) via the companion CLI.
  • Sanitization: There is no documentation of sanitization or escaping applied to external data before it is journaled or used to synthesize playbook candidates.
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading and installing a CLI binary and MCP server from remote repositories.
  • Evidence: Instructions suggest npx -y @mvanhorn/printing-press-library install and go install github.com/mvanhorn/printing-press-library/... (SKILL.md). These resources originate from the vendor's official repositories.
  • [DATA_EXFILTRATION]: The CLI binary includes a delivery sink feature that allows command output to be routed to external network endpoints.
  • Evidence: The --deliver webhook:<url> flag performs an HTTP POST of the command result to the specified URL (SKILL.md).
  • [DYNAMIC_EXECUTION]: The skill implements a 'playbook' system that dynamically reconstructs and executes command sequences.
  • Evidence: Playbooks are stored as JSON containing a steps array with cmd strings that are subject to slot substitution and execution in subsequent sessions (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 05:57 PM
Security Audit — agent-trust-hub — pp-flight-goat