pp-google-photos
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands by interpolating user-provided arguments into the google-photos-pp-cli binary calls. This approach requires input sanitization to prevent unintended command execution.\n- [DATA_EXFILTRATION]: The CLI utility includes a --deliver webhook: flag that allows routing command results to arbitrary external endpoints. It also contains a feedback mechanism capable of sending locally stored data to a remote URL if enabled by the user.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of external code from the author's GitHub and NPM repositories. These resources are part of the vendor's provided tooling for the skill's primary function.
Audit Metadata