pp-grants
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install dependencies from external registries. Specifically, it uses
npxto download@mvanhorn/printing-press-libraryfrom the NPM registry andgo installto fetchgrants-pp-clifrom GitHub (github.com/mvanhorn/printing-press-library). These resources are owned by the vendor infrastructure identified for this skill author. - [COMMAND_EXECUTION]: The skill's primary functionality is driven via the
Bashtool to execute thegrants-pp-clibinary for querying grant databases. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external public APIs (Grants.gov, NIH RePORTER, and NSF Awards). While this creates a potential surface for indirect prompt injection if the upstream data contained malicious instructions, the risk is minimized as the data sources are official US government research repositories.
Audit Metadata