pp-google-trends
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill guides the installation of its CLI tool and MCP server through the vendor's official channels, specifically using
npxfor the@mvanhorn/printing-press-librarypackage andgo installfor thegithub.com/mvanhorn/printing-press-libraryrepository. - [COMMAND_EXECUTION]: The primary function of this skill is the execution of shell commands via the
google-trends-pp-clibinary to interact with Google Trends data. - [DATA_EXFILTRATION]: The tool includes an output delivery feature (
--deliver webhook:<url>) that allows command results to be POSTed to external URLs. This is a documented capability for integrating search data with external workflows. - [CREDENTIALS_SAFE]: Authentication tokens and clearance cookies are managed securely in a local
credentials.tomlfile within the data directory, rather than being hardcoded or stored in insecure locations. - [INDIRECT_PROMPT_INJECTION]: As the skill ingests search data from external sources (Google Trends) and possesses write capabilities (file output and webhooks), it maintains an inherent attack surface for indirect prompt injection. However, it incorporates standard defenses such as XSSI string stripping.
Audit Metadata