pp-pdok-location
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install a CLI binary using
npxandgo installfrom repositories associated with the vendor (mvanhorn).- [COMMAND_EXECUTION]: The skill enables the execution of thepdok-location-pp-clibinary to interact with official Dutch geospatial services via allowed bash tools.- [DATA_EXFILTRATION]: A built-in feature of the CLI tool,--deliver webhook:<url>, allows command output to be sent to an arbitrary external network endpoint.- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface when processing external data: - Ingestion points: Reads external CSV files in
batch geocodeand processes user-supplied strings inresolveandsearchcommands. - Boundary markers: No explicit instructions are provided to the agent to treat input as untrusted or to ignore embedded commands.
- Capability inventory: The binary is capable of network requests and writing to the local file system.
- Sanitization: No input validation or content filtering for ingested data is mentioned in the skill documentation.
Audit Metadata