pp-luma

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions for the agent to install external binaries using 'go install' and 'npx' from the vendor's repository at github.com/mvanhorn/printing-press-library.
  • [EXTERNAL_DOWNLOADS]: Dependencies and CLI tools are fetched from external sources including GitHub and the NPM registry.
  • [DATA_EXFILTRATION]: The CLI tool includes a '--deliver webhook:' feature that allows command results to be transmitted to arbitrary external endpoints. It also supports a feedback mechanism that can POST data to a remote server if the LUMA_FEEDBACK_ENDPOINT environment variable is configured.
  • [PROMPT_INJECTION]: The skill processes untrusted public content from the Luma events platform, creating a risk of indirect prompt injection.
  • Ingestion points: Event titles, descriptions, and category metadata fetched via 'luma-pp-cli events list' and 'luma-pp-cli calendars'.
  • Boundary markers: The agent uses the '--agent' flag which outputs results in a structured JSON format, providing machine-readable boundaries.
  • Capability inventory: The skill has the ability to execute shell commands, write to local files (e.g., '.ics' files), and perform network operations via webhooks.
  • Sanitization: There is no mention of explicit sanitization or filtering of the external event data before it is presented to the agent.
  • [COMMAND_EXECUTION]: The skill relies on the agent's ability to execute the 'luma-pp-cli' binary with various arguments and flags to perform its functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 05:35 AM
Security Audit — agent-trust-hub — pp-luma