pp-is-agentic

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the is-agentic-pp-cli tool using npx from the @mvanhorn/printing-press-library package and via go install from the vendor's repository at github.com/mvanhorn/printing-press-library.
  • [DYNAMIC_EXECUTION]: Implements a playbook system through the recall and teach commands where the CLI returns a sequence of shell commands (Playbook.steps) to the agent. The instructions direct the agent to execute these commands, which are synthesized and stored in the CLI's local database from previous operations.
  • [DATA_EXFILTRATION]: Includes a --deliver webhook:<url> flag that POSTs command output to an arbitrary external URL. This creates a potential path for exfiltrating data processed by the skill to external endpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from public websites and incorporates it into a local learning loop. This ingestion surface, combined with the ability to generate future command playbooks based on that data, presents an indirect prompt injection risk.
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to download and execute code from remote repositories via npx and go install to set up the necessary CLI and MCP binaries.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 02:09 AM
Security Audit — agent-trust-hub — pp-is-agentic