pp-makerworld
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
makerworld-pp-clitool usingnpx -y @mvanhorn/printing-press-libraryorgo install github.com/mvanhorn/printing-press-library/.... These resources are managed by the skill's author. - [COMMAND_EXECUTION]: The skill requires the execution of shell commands to install, verify, and run the
makerworld-pp-clibinary. It handles user arguments via a$ARGUMENTSpattern to determine whether to perform an installation or execute a search command. - [DATA_EXFILTRATION]: The CLI tool documented in the skill includes a
--deliver webhook:<url>flag, which allows the agent to POST command results directly to a remote URL. While a legitimate automation feature, it represents a data routing capability that should be monitored. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill fetches and processes external 3D model data (titles, tags, descriptions) from the MakerWorld public catalog (SKILL.md).
- Boundary markers: The skill uses the
--agentflag to ensure output is delivered in a structured JSON envelope, which helps distinguish data from instructions. - Capability inventory: The skill has the ability to execute shell commands via the
Read Bashtool. - Sanitization: There is no mention of sanitization for the external catalog content before it is processed by the agent.
Audit Metadata