pp-plexctl
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the
plexctl-pp-clitool usingnpxfrom@mvanhorn/printing-press-libraryor viago installfromgithub.com/mvanhorn/printing-press-library. These resources are associated with the author context and are documented neutrally. - [DATA_EXFILTRATION]: The CLI tool supports a
--deliver webhook:<url>flag that allows routing command output—which may include sensitive media library metadata, server logs, or activity history—to arbitrary external URLs via HTTP POST requests. - [INDIRECT_PROMPT_INJECTION]: The skill implements an 'Automatic Learning' system where user queries are processed by a
recallandteachloop. This loop synthesizes 'playbooks' (choreographed command sequences) which are then executed by the agent. This represents an ingestion surface for untrusted data that could influence future tool behavior. - Ingestion points:
recallandteachcommands inSKILL.mdingest user-supplied queries. - Boundary markers: None are specified for the interpolation of query entities into command slots.
- Capability inventory:
plexctl-pp-cliallows for command execution, file writing, and network operations. - Sanitization: The documentation does not specify sanitization or validation for the
{slot}substitution mechanism used when replaying playbooks. - [DYNAMIC_EXECUTION]: The tool supports 'Playbooks,' which are JSON-defined sequences of commands with variable substitution. The skill describes how these playbooks are automatically synthesized from session journals and subsequently executed, representing a runtime code generation and execution pattern.
Audit Metadata