pp-is-agentic
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches and installs the
is-agentic-pp-clitool usingnpxfrom the@mvanhorn/printing-press-librarypackage and viago installfrom the vendor's repository atgithub.com/mvanhorn/printing-press-library. - [DYNAMIC_EXECUTION]: Implements a playbook system through the
recallandteachcommands where the CLI returns a sequence of shell commands (Playbook.steps) to the agent. The instructions direct the agent to execute these commands, which are synthesized and stored in the CLI's local database from previous operations. - [DATA_EXFILTRATION]: Includes a
--deliver webhook:<url>flag that POSTs command output to an arbitrary external URL. This creates a potential path for exfiltrating data processed by the skill to external endpoints. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from public websites and incorporates it into a local learning loop. This ingestion surface, combined with the ability to generate future command playbooks based on that data, presents an indirect prompt injection risk.
- [REMOTE_CODE_EXECUTION]: The skill provides instructions to download and execute code from remote repositories via
npxandgo installto set up the necessary CLI and MCP binaries.
Audit Metadata