pp-keyword-planner
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The installation instructions direct the agent to fetch the keyword-planner-pp-cli tool using npx from the npm registry (@mvanhorn/printing-press-library) and via go install from the author's GitHub repository (github.com/mvanhorn/printing-press-library). These resources are associated with the vendor and are documented for transparency.
- [REMOTE_CODE_EXECUTION]: The skill includes instructions to download and execute code from remote sources during the installation process through npx and go install commands.
- [COMMAND_EXECUTION]: The skill provides numerous examples for the agent to execute the keyword-planner-pp-cli binary locally for functions such as keyword discovery, historical metric retrieval, and evidence management.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the Google Ads API, which could be exploited for indirect prompt injection. 1. Ingestion points: Data entering the agent's context through the ideas and historical metrics commands (referenced in SKILL.md). 2. Boundary markers: The skill does not define specific delimiters to isolate API-sourced data from internal agent instructions. 3. Capability inventory: The agent has the Read Bash tool and access to a CLI that performs network operations and local file writes to snapshots.db. 4. Sanitization: While the CLI includes a safe-stats command to manage metric integrity, the SKILL.md provides no guidance for the agent to sanitize or ignore instructions potentially embedded in the API responses.
Audit Metadata