pp-grants

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install dependencies from external registries. Specifically, it uses npx to download @mvanhorn/printing-press-library from the NPM registry and go install to fetch grants-pp-cli from GitHub (github.com/mvanhorn/printing-press-library). These resources are owned by the vendor infrastructure identified for this skill author.
  • [COMMAND_EXECUTION]: The skill's primary functionality is driven via the Bash tool to execute the grants-pp-cli binary for querying grant databases.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external public APIs (Grants.gov, NIH RePORTER, and NSF Awards). While this creates a potential surface for indirect prompt injection if the upstream data contained malicious instructions, the risk is minimized as the data sources are official US government research repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 06:50 AM
Security Audit — agent-trust-hub — pp-grants