pp-nutrition

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and install external binaries and packages from the author's GitHub repository and NPM scope using npx and go install commands.
  • Evidence: npx -y @mvanhorn/printing-press-library install nutrition --cli-only in SKILL.md.
  • Evidence: go install github.com/mvanhorn/printing-press-library/library/food-and-dining/nutrition/cmd/nutrition-pp-cli@latest in SKILL.md.
  • [DATA_EXFILTRATION]: The skill documents an output delivery feature that allows routing command results to arbitrary external URLs via webhooks. This capability could be used to transmit locally cached nutrition logs, dietary diaries, or configuration details to a remote server.
  • Evidence: The --deliver webhook:<url> flag described in the Output Delivery section of SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes food nutrition data from external sources (USDA FoodData Central and NutritionValue.org), creating a surface where untrusted data is ingested into the agent context.
  • Ingestion points: Data from USDA and NutritionValue.org ingested via food, enrich, and rank commands.
  • Boundary markers: The skill does not define specific delimiters or explicit instructions to ignore embedded content within retrieved food records.
  • Capability inventory: The tool can execute shell commands via the nutrition-pp-cli binary and perform network POST requests via the webhook delivery sink.
  • Sanitization: No sanitization or filtering is mentioned for data retrieved from external APIs before it is interpolated into the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 10:17 PM
Security Audit — agent-trust-hub — pp-nutrition