pp-pbs
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the user to install binary tools using
npx -y @mvanhorn/printing-press-libraryandgo install github.com/mvanhorn/.... These resources are owned by the vendor 'mvanhorn' and are considered safe under vendor trust rules, but represent remote code execution at installation time. - [DATA_EXFILTRATION]: The CLI supports a
--deliver webhook:<url>flag, which POSTs command output to an external endpoint. This feature could be leveraged to exfiltrate sensitive data if the sink URL is controlled by an attacker. - [DYNAMIC_EXECUTION]: The skill implements a 'learning loop' where the agent is instructed to retrieve and execute 'playbooks' (sequences of shell commands) from a local store via the
recallcommand. The execution of these stored strings constitutes dynamic execution. - [INDIRECT_PROMPT_INJECTION]: The skill ingests machine-hostile weekly price files from the Pakistan Bureau of Statistics and uses a
teachmechanism to persist mappings between queries and resources. A lack of sanitization could allow malicious content in the external source or a poisonedteachcommand to influence future automated 'playbook' actions. - Ingestion points: Parses external report files and index pages; accepts user-provided queries for the
teachandrecallcommands. - Boundary markers: None identified in the instruction text or command logic.
- Capability inventory: Executes shell commands, performs network POST requests via webhooks, and writes files via the
file:<path>sink. - Sanitization: No specific sanitization or validation of external cell values or stored playbooks is described.
- [COMMAND_EXECUTION]: The skill involves the direct execution of the
pbs-pp-clibinary with various arguments and usesnpxandgofor environment setup.
Audit Metadata