pp-luma
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions for the agent to install external binaries using 'go install' and 'npx' from the vendor's repository at github.com/mvanhorn/printing-press-library.
- [EXTERNAL_DOWNLOADS]: Dependencies and CLI tools are fetched from external sources including GitHub and the NPM registry.
- [DATA_EXFILTRATION]: The CLI tool includes a '--deliver webhook:' feature that allows command results to be transmitted to arbitrary external endpoints. It also supports a feedback mechanism that can POST data to a remote server if the LUMA_FEEDBACK_ENDPOINT environment variable is configured.
- [PROMPT_INJECTION]: The skill processes untrusted public content from the Luma events platform, creating a risk of indirect prompt injection.
- Ingestion points: Event titles, descriptions, and category metadata fetched via 'luma-pp-cli events list' and 'luma-pp-cli calendars'.
- Boundary markers: The agent uses the '--agent' flag which outputs results in a structured JSON format, providing machine-readable boundaries.
- Capability inventory: The skill has the ability to execute shell commands, write to local files (e.g., '.ics' files), and perform network operations via webhooks.
- Sanitization: There is no mention of explicit sanitization or filtering of the external event data before it is presented to the agent.
- [COMMAND_EXECUTION]: The skill relies on the agent's ability to execute the 'luma-pp-cli' binary with various arguments and flags to perform its functions.
Audit Metadata