pp-jobber
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install a CLI binary from the vendor's scope on npm and their GitHub repository.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external Jobber API accounts and local SQLite databases, creating a surface where instructions embedded in that data could be interpreted by the agent. * Ingestion points: Synced data from Jobber API and local SQLite storage. * Boundary markers: No specific delimiters or boundary markers are defined in the skill instructions. * Capability inventory: Shell execution of the jobber-pp-cli tool and optional network exfiltration via webhooks. * Sanitization: The instructions do not specify any validation or sanitization routines for the external data.
- [DATA_EXFILTRATION]: The skill documents an output delivery feature that allows the agent to route command results to an external webhook URL.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the jobber-pp-cli binary, which includes support for ad-hoc SQL queries.
Audit Metadata