pp-nvd

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends installing command-line tools and MCP servers directly from the vendor's repositories on GitHub and NPM.
  • Directs users to use go install for packages under github.com/mvanhorn/printing-press-library.
  • References the @mvanhorn/printing-press package for installation via npx.
  • [DATA_EXFILTRATION]: The CLI tool provides built-in capabilities to route its output to external network destinations.
  • The --deliver flag supports the webhook:<url> scheme, enabling the POSTing of tool results to remote servers.
  • A feedback mechanism is documented which can be configured to transmit data to a remote endpoint via the NVD_FEEDBACK_ENDPOINT environment variable.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 06:03 PM