pp-fpi-india

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of a command-line interface (CLI) tool from external sources. It provides instructions to use npx to install @mvanhorn/printing-press-library or go install to fetch the source from github.com/mvanhorn/printing-press-library. These resources are managed by the skill's author.
  • [COMMAND_EXECUTION]: The skill's primary function is to execute the fpi-india-pp-cli binary with various arguments to retrieve and analyze financial data. It uses the Bash tool to perform these operations.
  • [DATA_EXFILTRATION]: The CLI tool described in the skill features an output delivery system (--deliver) that includes a webhook:<url> sink. This capability allows the agent to transmit the output of commands to any external URL. While presented as a functional feature for data routing, it establishes a potential pathway for data exfiltration if the agent is directed to send sensitive data to an untrusted endpoint.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external financial reports (NSDL and CDSL). This ingestion of third-party data into the agent's context creates a surface for indirect prompt injection, although the structured nature of the data (FPI flows) reduces this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 09:18 AM
Security Audit — agent-trust-hub — pp-fpi-india