pp-immovlan

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and install a CLI binary and an MCP server from the vendor's official GitHub repository (github.com/mvanhorn/printing-press-library) and NPM package scope (@mvanhorn/printing-press-library).
  • [COMMAND_EXECUTION]: The skill primarily operates by executing a locally installed binary, immovlan-pp-cli, to perform searches, enrich data, and manage a local SQLite database.
  • [DATA_EXFILTRATION]: The command execution framework supports a --deliver webhook:<url> flag, which enables the routing of command output to external URLs. While a legitimate feature for integration, it provides a mechanism for transmitting data to remote servers.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted real estate listing data from external websites (immovlan.be).
  • Ingestion points: The find, enrich, and listings search commands fetch data from the public web.
  • Boundary markers: No specific delimiters or safety instructions are defined for the data processed by the tool.
  • Capability inventory: The agent has the ability to execute shell commands (the CLI itself), write to a local SQLite database, and send data via webhooks.
  • Sanitization: The skill includes specific advice to avoid shell injection when handling user queries by writing them to files before processing, but does not specify sanitization for the scraped web content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 07:26 AM
Security Audit — agent-trust-hub — pp-immovlan