pp-pexels
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires downloading the
pexels-pp-clibinary vianpxorgo install. The sources provided aregithub.com/mvanhorn/printing-press-libraryand the@mvanhorn/printing-press-librarynpm package. - [REMOTE_CODE_EXECUTION]: The installation process involves running code directly from npm via
npxand installing from GitHub viago install. These patterns execute remote content during the setup phase. - [COMMAND_EXECUTION]: The skill relies on executing shell commands through the
Read Bashtool to install, verify, and run the Pexels CLI. - [DATA_EXFILTRATION]: The skill documents features that allow routing output to external URLs using the
--deliver webhook:<url>flag and sending feedback to an endpoint defined byPEXELS_FEEDBACK_ENDPOINT. These documented capabilities allow for network transmission of data gathered by the tool. - [INDIRECT_PROMPT_INJECTION]: The skill ingests media metadata and search results from the Pexels API (Ingestion points: photo/video search results). This external content is processed by the agent and can be written to files or sent over the network (Capability inventory: file writing, webhook POSTing). While structured JSON is used (Boundary markers:
--agentflag), the skill does not explicitly mention sanitization of the external API content before it enters the agent's context.
Audit Metadata