pp-google-trends

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill guides the installation of its CLI tool and MCP server through the vendor's official channels, specifically using npx for the @mvanhorn/printing-press-library package and go install for the github.com/mvanhorn/printing-press-library repository.
  • [COMMAND_EXECUTION]: The primary function of this skill is the execution of shell commands via the google-trends-pp-cli binary to interact with Google Trends data.
  • [DATA_EXFILTRATION]: The tool includes an output delivery feature (--deliver webhook:<url>) that allows command results to be POSTed to external URLs. This is a documented capability for integrating search data with external workflows.
  • [CREDENTIALS_SAFE]: Authentication tokens and clearance cookies are managed securely in a local credentials.toml file within the data directory, rather than being hardcoded or stored in insecure locations.
  • [INDIRECT_PROMPT_INJECTION]: As the skill ingests search data from external sources (Google Trends) and possesses write capabilities (file output and webhooks), it maintains an inherent attack surface for indirect prompt injection. However, it incorporates standard defenses such as XSSI string stripping.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 12:34 AM
Security Audit — agent-trust-hub — pp-google-trends