pp-isitagentready

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads its primary executable from the author's GitHub repository (github.com/mvanhorn/printing-press-library/...) using go install and npx. As these resources belong to the vendor 'mvanhorn', they are considered standard installation procedures for the skill's functionality.
  • [COMMAND_EXECUTION]: The skill executes the isitagentready-pp-cli and isitagentready-pp-mcp binaries to perform website scans, manage scan history, and provide optimization advice. These commands are the intended purpose of the skill.
  • [DATA_EXFILTRATION]: The skill mentions a webhook delivery sink and a feedback mechanism. The feedback mechanism is local-only by default and only sends data to a user-configured environment variable (ISITAGENTREADY_FEEDBACK_ENDPOINT). The webhook delivery is an explicit opt-in feature for routing output and does not represent silent exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 10:56 PM
Security Audit — agent-trust-hub — pp-isitagentready