pp-mcpmarket
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes free-text user queries through its
recall,teach, andplaybookcommands, which can ingest untrusted data from the conversation history. - Ingestion points: User questions are passed as inputs to the
mcpmarket-pp-cli recall,teach, andplaybook amendcommands described in theAutomatic learningsection ofSKILL.md. - Boundary markers: The skill includes explicit defensive instructions and warnings (Step 4 and Step 6) for the agent to handle user input securely by writing it to temporary files (
--query-file) instead of using direct shell interpolation to prevent command injection. - Capability inventory: The skill requires
Read Bashto execute the CLI tool and local file-write capabilities to create the temporary query files for secure parameter passing. - Sanitization: The skill mandates the use of file-based input to bypass shell escaping issues, which is a proactive sanitization measure against shell injection.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install its core CLI binary and MCP server from the developer's repository.
- Evidence: Instructions in
SKILL.mdusenpx -y @mvanhorn/printing-press-libraryandgo install github.com/mvanhorn/printing-press-library/...to acquire the necessary tools. - [REMOTE_CODE_EXECUTION]: The installation process involves downloading and executing code from the developer's infrastructure to set up the environment.
- Evidence: The use of
npxandgo installtargets remote modules and source code to generate local executable binaries (mcpmarket-pp-cli,mcpmarket-pp-mcp). - [COMMAND_EXECUTION]: The skill's primary functionality is achieved by executing the
mcpmarket-pp-clibinary via shell commands to interact with the MCP Market catalog and manage local state.
Audit Metadata