pp-keyword-planner

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation instructions direct the agent to fetch the keyword-planner-pp-cli tool using npx from the npm registry (@mvanhorn/printing-press-library) and via go install from the author's GitHub repository (github.com/mvanhorn/printing-press-library). These resources are associated with the vendor and are documented for transparency.
  • [REMOTE_CODE_EXECUTION]: The skill includes instructions to download and execute code from remote sources during the installation process through npx and go install commands.
  • [COMMAND_EXECUTION]: The skill provides numerous examples for the agent to execute the keyword-planner-pp-cli binary locally for functions such as keyword discovery, historical metric retrieval, and evidence management.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the Google Ads API, which could be exploited for indirect prompt injection. 1. Ingestion points: Data entering the agent's context through the ideas and historical metrics commands (referenced in SKILL.md). 2. Boundary markers: The skill does not define specific delimiters to isolate API-sourced data from internal agent instructions. 3. Capability inventory: The agent has the Read Bash tool and access to a CLI that performs network operations and local file writes to snapshots.db. 4. Sanitization: While the CLI includes a safe-stats command to manage metric integrity, the SKILL.md provides no guidance for the agent to sanitize or ignore instructions potentially embedded in the API responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:36 PM
Security Audit — agent-trust-hub — pp-keyword-planner