pp-mufap
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user/agent to download and install packages from the vendor's NPM registry (@mvanhorn/printing-press-library) and GitHub repository (github.com/mvanhorn/printing-press-library).
- [REMOTE_CODE_EXECUTION]: The skill leverages go install and npx to fetch and execute binaries from remote vendor-owned sources, specifically to install the mufap-pp-cli and mufap-pp-mcp tools.
- [COMMAND_EXECUTION]: The primary functionality of the skill is to execute the mufap-pp-cli binary with various flags to query, mirror, and analyze mutual fund data.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the MUFAP association website, which could be manipulated by an external party to influence agent behavior.
- Ingestion points: Mutual fund daily NAVs, monthly asset allocation, and net sales data fetched via the backfill, panel, and exposure commands in mufap-pp-cli from the MUFAP website.
- Boundary markers: None. The skill does not instruct the agent to use specific delimiters or protective instructions when processing data from the external source.
- Capability inventory: The skill can execute shell commands (bash), read and write to a local SQLite database (data.db), and perform network requests to the MUFAP site (via the CLI).
- Sanitization: The CLI performs data cleanup for numerical parsing (e.g., handling accounting notation for negatives), but there is no evidence of security-focused sanitization to prevent prompt injection into the LLM context.
- [DYNAMIC_EXECUTION]: The skill implements an 'Automatic Learning' loop that journals agent interactions and synthesizes 'playbooks' (sequences of shell commands) from the local history. These playbooks are then executed in future sessions to resolve similar query families.
Audit Metadata