pp-mobbin

Warn

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill facilitates the extraction of sensitive session cookies from the local Chrome browser via the auth login --chrome command to authenticate with Mobbin services.
  • [DATA_EXFILTRATION]: The CLI tool supports a --deliver webhook:<url> argument, enabling the transmission of command outputs to arbitrary remote servers.
  • [COMMAND_EXECUTION]: The skill functions by executing a local binary (mobbin-pp-cli) which performs various system-level tasks, including file writes, directory management, and network requests.
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the CLI tool from the author's GitHub repository using go install and npx (Node.js package: @mvanhorn/printing-press-library).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 10, 2026, 10:51 PM
Security Audit — agent-trust-hub — pp-mobbin