pp-lda-gov

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the lda-gov-pp-cli tool via npx from the @mvanhorn NPM registry and go install from the mvanhorn GitHub repository. These sources are associated with the skill's verified author and are used for providing the primary functionality.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to run CLI commands for processing lobbying filings, syncing data to local SQLite databases, and performing entity resolution.
  • [DATA_EXFILTRATION]: The underlying CLI tool supports a --deliver webhook:<url> flag, which allows the output of commands to be sent to a specified URL. This feature is intended for data routing and uses the public information retrieved from the Lobbying Disclosure Act API.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the external LDA.gov API (ingestion point: lda-gov-pp-cli via SKILL.md). Boundary markers include a JSON response envelope and the --select flag to filter fields. The capability inventory includes Bash execution for data analysis. Sanitization is achieved through structured JSON output and user-defined field selection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 12:15 PM
Security Audit — agent-trust-hub — pp-lda-gov