pp-fpi-india
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of a command-line interface (CLI) tool from external sources. It provides instructions to use
npxto install@mvanhorn/printing-press-libraryorgo installto fetch the source fromgithub.com/mvanhorn/printing-press-library. These resources are managed by the skill's author. - [COMMAND_EXECUTION]: The skill's primary function is to execute the
fpi-india-pp-clibinary with various arguments to retrieve and analyze financial data. It uses theBashtool to perform these operations. - [DATA_EXFILTRATION]: The CLI tool described in the skill features an output delivery system (
--deliver) that includes awebhook:<url>sink. This capability allows the agent to transmit the output of commands to any external URL. While presented as a functional feature for data routing, it establishes a potential pathway for data exfiltration if the agent is directed to send sensitive data to an untrusted endpoint. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external financial reports (NSDL and CDSL). This ingestion of third-party data into the agent's context creates a surface for indirect prompt injection, although the structured nature of the data (FPI flows) reduces this risk.
Audit Metadata