pp-giustizia-amministrativa

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the giustizia-amministrativa-pp-cli via the @mvanhorn/printing-press-library package from the npm registry, which is a resource owned by the vendor.\n- [REMOTE_CODE_EXECUTION]: Installation is performed via npx, which downloads and executes remote code at runtime; however, this is a standard distribution method for this vendor's tools.\n- [COMMAND_EXECUTION]: The skill executes the giustizia-amministrativa-pp-cli binary to search for and download legal rulings and court orders.\n- [DATA_EXFILTRATION]: The CLI tool includes a --deliver webhook:<url> feature that allows sending the output of commands to external HTTP endpoints, which serves as a potential exfiltration vector if misused.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of processing external judicial content.\n
  • Ingestion points: Judicial documents (sentenze, ordinanze) are retrieved from the Italian administrative justice portal.\n
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following instructions potentially embedded in the retrieved legal texts.\n
  • Capability inventory: The skill utilizes shell execution, local file writing, and remote webhook delivery.\n
  • Sanitization: While the tool claims to produce "clean Markdown," no specific sanitization or filtering logic is described to mitigate malicious injection in the source documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 12:14 PM
Security Audit — agent-trust-hub — pp-giustizia-amministrativa