pp-flight-goat
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (flight fares, route info, WiFi speeds) from various third-party providers.
- Ingestion points: Data returned from search and status commands including
flights,dates,explore,soar,award, andwifi(SKILL.md). - Boundary markers: The instructions do not define explicit delimiters or 'ignore embedded instructions' warnings for processing the results from these tools.
- Capability inventory: The skill has the capability to execute shell commands, write to a local SQLite store (
teach), and send data to external URLs (webhook) via the companion CLI. - Sanitization: There is no documentation of sanitization or escaping applied to external data before it is journaled or used to synthesize playbook candidates.
- [EXTERNAL_DOWNLOADS]: The skill requires downloading and installing a CLI binary and MCP server from remote repositories.
- Evidence: Instructions suggest
npx -y @mvanhorn/printing-press-library installandgo install github.com/mvanhorn/printing-press-library/...(SKILL.md). These resources originate from the vendor's official repositories. - [DATA_EXFILTRATION]: The CLI binary includes a delivery sink feature that allows command output to be routed to external network endpoints.
- Evidence: The
--deliver webhook:<url>flag performs an HTTP POST of the command result to the specified URL (SKILL.md). - [DYNAMIC_EXECUTION]: The skill implements a 'playbook' system that dynamically reconstructs and executes command sequences.
- Evidence: Playbooks are stored as JSON containing a
stepsarray withcmdstrings that are subject to slot substitution and execution in subsequent sessions (SKILL.md).
Audit Metadata