pp-hackernews

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and install external binaries and packages from vendor-controlled repositories.
  • Evidence: npx -y @mvanhorn/printing-press-library install hackernews --cli-only and go install github.com/mvanhorn/printing-press-library/library/media-and-entertainment/hackernews/cmd/hackernews-pp-cli@latest.
  • [REMOTE_CODE_EXECUTION]: The installation process involves executing code downloaded from remote repositories (NPM and GitHub) associated with the vendor.
  • Evidence: The use of npx and go install to fetch and run setup scripts or binaries from the mvanhorn vendor space.
  • [DATA_EXFILTRATION]: The CLI includes a --deliver webhook:<url> flag that allows sending command output to an arbitrary external URL, providing a mechanism for exfiltrating processed data.
  • Evidence: Documentation for the --deliver flag describing the webhook:<url> sink which POSTs output to a provided endpoint.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from Hacker News, which consists of untrusted user-generated content that could contain malicious instructions.
  • Ingestion points: Data is retrieved from Hacker News via commands like stories, search, pulse, and hiring (SKILL.md).
  • Boundary markers: None identified in the provided instructions or examples.
  • Capability inventory: The skill can execute shell commands (hackernews-pp-cli), perform network operations (fetching HN data, posting to webhooks via the deliver flag), and write to a local SQLite store.
  • Sanitization: No explicit sanitization or filtering of external content is mentioned before processing or display.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:41 AM
Security Audit — agent-trust-hub — pp-hackernews