pp-navitime

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install a command-line tool from the author's repositories.
  • Evidence: Installation commands include npx -y @mvanhorn/printing-press-library install navitime --cli-only and go install github.com/mvanhorn/printing-press-library/library/travel/navitime/cmd/navitime-pp-cli@latest. These sources correspond to the skill author's infrastructure.
  • [COMMAND_EXECUTION]: The skill is designed to invoke the navitime-pp-cli binary via the bash environment to process travel queries.
  • Evidence: The skill utilizes the Read Bash tool to run commands such as navitime-pp-cli places search and navitime-pp-cli routes search.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from external travel services (NAVITIME), which acts as a potential injection surface.
  • Ingestion points: Data is ingested via the search results returned by the navitime-pp-cli tool from NAVITIME services.
  • Boundary markers: No explicit boundary markers or specialized instructions are defined to separate external data from agent instructions.
  • Capability inventory: The skill has the capability to execute shell commands and read/write to a local cache directory.
  • Sanitization: There is no documentation of sanitization or validation performed on the external travel data before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 11:57 AM
Security Audit — agent-trust-hub — pp-navitime