pp-mcpmarket

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes free-text user queries through its recall, teach, and playbook commands, which can ingest untrusted data from the conversation history.
  • Ingestion points: User questions are passed as inputs to the mcpmarket-pp-cli recall, teach, and playbook amend commands described in the Automatic learning section of SKILL.md.
  • Boundary markers: The skill includes explicit defensive instructions and warnings (Step 4 and Step 6) for the agent to handle user input securely by writing it to temporary files (--query-file) instead of using direct shell interpolation to prevent command injection.
  • Capability inventory: The skill requires Read Bash to execute the CLI tool and local file-write capabilities to create the temporary query files for secure parameter passing.
  • Sanitization: The skill mandates the use of file-based input to bypass shell escaping issues, which is a proactive sanitization measure against shell injection.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install its core CLI binary and MCP server from the developer's repository.
  • Evidence: Instructions in SKILL.md use npx -y @mvanhorn/printing-press-library and go install github.com/mvanhorn/printing-press-library/... to acquire the necessary tools.
  • [REMOTE_CODE_EXECUTION]: The installation process involves downloading and executing code from the developer's infrastructure to set up the environment.
  • Evidence: The use of npx and go install targets remote modules and source code to generate local executable binaries (mcpmarket-pp-cli, mcpmarket-pp-mcp).
  • [COMMAND_EXECUTION]: The skill's primary functionality is achieved by executing the mcpmarket-pp-cli binary via shell commands to interact with the MCP Market catalog and manage local state.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 06:23 AM
Security Audit — agent-trust-hub — pp-mcpmarket