pp-github-intel

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the github-intel-pp-cli binary. This includes capability discovery via which, repository metadata retrieval, and advisory listing. These are standard operations for a CLI-based research tool.
  • [EXTERNAL_DOWNLOADS]: The skill provides installation instructions using npx (targeting the author's package @mvanhorn/printing-press-library) and go install (targeting the author's GitHub repository github.com/mvanhorn/printing-press-library). These resources are owned by the vendor 'mvanhorn' and are consistent with the skill's stated purpose.
  • [DATA_EXFILTRATION]: While the skill includes a --deliver webhook:<url> feature that can POST output to a URL, this is documented as a user-configurable sink for routing command results. The default behavior is local, and the skill explicitly limits itself to read-only operations for inspection and analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 05:17 AM
Security Audit — agent-trust-hub — pp-github-intel