pp-navitime
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install a command-line tool from the author's repositories.
- Evidence: Installation commands include
npx -y @mvanhorn/printing-press-library install navitime --cli-onlyandgo install github.com/mvanhorn/printing-press-library/library/travel/navitime/cmd/navitime-pp-cli@latest. These sources correspond to the skill author's infrastructure. - [COMMAND_EXECUTION]: The skill is designed to invoke the
navitime-pp-clibinary via the bash environment to process travel queries. - Evidence: The skill utilizes the
Read Bashtool to run commands such asnavitime-pp-cli places searchandnavitime-pp-cli routes search. - [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from external travel services (NAVITIME), which acts as a potential injection surface.
- Ingestion points: Data is ingested via the search results returned by the
navitime-pp-clitool from NAVITIME services. - Boundary markers: No explicit boundary markers or specialized instructions are defined to separate external data from agent instructions.
- Capability inventory: The skill has the capability to execute shell commands and read/write to a local cache directory.
- Sanitization: There is no documentation of sanitization or validation performed on the external travel data before it is presented to the agent.
Audit Metadata