pp-nepra
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a 'learning loop' (via the
teach,recall, andplaybookcommands) that ingests user-supplied queries and stores them locally to influence future agent behavior and command selection. - Ingestion points: The
teachandplaybook amendcommands inSKILL.mdingest arbitrary strings from user queries into the tool's local state. - Boundary markers: No technical delimiters or 'ignore' instructions are described for the stored data, relying instead on manual PII stripping instructions.
- Capability inventory: The skill uses
nepra-pp-cli, which can execute shell commands, perform network requests, and write to local files. - Sanitization: No explicit technical sanitization or validation is described for the stored queries or the command-slot substitution mechanism.
- [DYNAMIC_EXECUTION]: The skill's 'playbook' feature allows the execution of sequences of shell commands defined in JSON structures with variable substitution (
{slot}). This runtime assembly and execution of commands based on stored data is a potential security risk if the local learning store is manipulated. - [DATA_EXFILTRATION]: The CLI includes a
--deliver webhook:<url>feature that allows the output of any command to be sent to an arbitrary external URL via an HTTP POST request. While a documented capability, it provides a built-in mechanism for exfiltrating data. - [COMMAND_EXECUTION]: The skill provides instructions for installing and executing a custom binary,
nepra-pp-cli, which handles the primary logic of the skill. - [EXTERNAL_DOWNLOADS]: The skill fetches its primary CLI tool from the author's NPM registry (
@mvanhorn/printing-press-library) and GitHub repository (github.com/mvanhorn/printing-press-library). These resources are managed by the skill's author.
Audit Metadata