pp-opensnow

Pass

Audited by Gen Agent Trust Hub on May 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and installs external components from the vendor's GitHub organization and NPM namespace. These resources are owned by the skill author.- [DATA_EXFILTRATION]: The CLI tool supports a webhook delivery feature, which allows routing command outputs to an external URL via HTTP POST. This is a documented functionality of the tool.- [COMMAND_EXECUTION]: The skill operates by executing shell commands via the allowed tools to interact with the CLI binary for data retrieval and configuration.- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests external mountain weather data and digests from the OpenSnow API. The tool includes HTML stripping to clean processed text.
Audit Metadata
Risk Level
SAFE
Analyzed
May 9, 2026, 08:47 PM