pp-pexels

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading the pexels-pp-cli binary via npx or go install. The sources provided are github.com/mvanhorn/printing-press-library and the @mvanhorn/printing-press-library npm package.
  • [REMOTE_CODE_EXECUTION]: The installation process involves running code directly from npm via npx and installing from GitHub via go install. These patterns execute remote content during the setup phase.
  • [COMMAND_EXECUTION]: The skill relies on executing shell commands through the Read Bash tool to install, verify, and run the Pexels CLI.
  • [DATA_EXFILTRATION]: The skill documents features that allow routing output to external URLs using the --deliver webhook:<url> flag and sending feedback to an endpoint defined by PEXELS_FEEDBACK_ENDPOINT. These documented capabilities allow for network transmission of data gathered by the tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests media metadata and search results from the Pexels API (Ingestion points: photo/video search results). This external content is processed by the agent and can be written to files or sent over the network (Capability inventory: file writing, webhook POSTing). While structured JSON is used (Boundary markers: --agent flag), the skill does not explicitly mention sanitization of the external API content before it enters the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 10:28 AM
Security Audit — agent-trust-hub — pp-pexels