pp-nccpl

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the nccpl-pp-cli and nccpl-pp-mcp tools from the author's GitHub repository (github.com/mvanhorn/printing-press-library) and npm registry (@mvanhorn/printing-press-library). These are documented vendor-supplied resources.
  • [COMMAND_EXECUTION]: The skill's primary function is to execute shell commands using the nccpl-pp-cli binary through the Bash tool to retrieve and manage local financial data panels.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an "Automatic learning" loop that processes user queries and session history to optimize future interactions. This creates a vulnerability surface where data encountered by the agent can influence its future logic.
  • Ingestion points: Stored in SKILL.md as logic that processes user queries, session journals (learn_events), and feedback (feedback.jsonl).
  • Boundary markers: No specific boundary markers or delimiters are described for isolating untrusted input within the learning store.
  • Capability inventory: The system can execute any nccpl-pp-cli command via Bash, including network-active commands like capture or sync.
  • Sanitization: The instructions include a manual rule to strip PII before "teaching" the system, but there is no automated sanitization for command-altering payloads.
  • [DYNAMIC_EXECUTION]: The "Playbook" system automates workflows by substituting variables into command templates ({slot}). These synthesized commands are then executed in the shell, representing a form of dynamic command generation based on stored session patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:50 AM
Security Audit — agent-trust-hub — pp-nccpl