pp-nutrition
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and install external binaries and packages from the author's GitHub repository and NPM scope using
npxandgo installcommands. - Evidence:
npx -y @mvanhorn/printing-press-library install nutrition --cli-onlyin SKILL.md. - Evidence:
go install github.com/mvanhorn/printing-press-library/library/food-and-dining/nutrition/cmd/nutrition-pp-cli@latestin SKILL.md. - [DATA_EXFILTRATION]: The skill documents an output delivery feature that allows routing command results to arbitrary external URLs via webhooks. This capability could be used to transmit locally cached nutrition logs, dietary diaries, or configuration details to a remote server.
- Evidence: The
--deliver webhook:<url>flag described in the Output Delivery section of SKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes food nutrition data from external sources (USDA FoodData Central and NutritionValue.org), creating a surface where untrusted data is ingested into the agent context.
- Ingestion points: Data from USDA and NutritionValue.org ingested via
food,enrich, andrankcommands. - Boundary markers: The skill does not define specific delimiters or explicit instructions to ignore embedded content within retrieved food records.
- Capability inventory: The tool can execute shell commands via the
nutrition-pp-clibinary and perform network POST requests via thewebhookdelivery sink. - Sanitization: No sanitization or filtering is mentioned for data retrieved from external APIs before it is interpolated into the agent context.
Audit Metadata