pp-pdok-location

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install a CLI binary using npx and go install from repositories associated with the vendor (mvanhorn).- [COMMAND_EXECUTION]: The skill enables the execution of the pdok-location-pp-cli binary to interact with official Dutch geospatial services via allowed bash tools.- [DATA_EXFILTRATION]: A built-in feature of the CLI tool, --deliver webhook:<url>, allows command output to be sent to an arbitrary external network endpoint.- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface when processing external data:
  • Ingestion points: Reads external CSV files in batch geocode and processes user-supplied strings in resolve and search commands.
  • Boundary markers: No explicit instructions are provided to the agent to treat input as untrusted or to ignore embedded commands.
  • Capability inventory: The binary is capable of network requests and writing to the local file system.
  • Sanitization: No input validation or content filtering for ingested data is mentioned in the skill documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 10:59 PM
Security Audit — agent-trust-hub — pp-pdok-location