pp-plexctl

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the plexctl-pp-cli tool using npx from @mvanhorn/printing-press-library or via go install from github.com/mvanhorn/printing-press-library. These resources are associated with the author context and are documented neutrally.
  • [DATA_EXFILTRATION]: The CLI tool supports a --deliver webhook:<url> flag that allows routing command output—which may include sensitive media library metadata, server logs, or activity history—to arbitrary external URLs via HTTP POST requests.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an 'Automatic Learning' system where user queries are processed by a recall and teach loop. This loop synthesizes 'playbooks' (choreographed command sequences) which are then executed by the agent. This represents an ingestion surface for untrusted data that could influence future tool behavior.
  • Ingestion points: recall and teach commands in SKILL.md ingest user-supplied queries.
  • Boundary markers: None are specified for the interpolation of query entities into command slots.
  • Capability inventory: plexctl-pp-cli allows for command execution, file writing, and network operations.
  • Sanitization: The documentation does not specify sanitization or validation for the {slot} substitution mechanism used when replaying playbooks.
  • [DYNAMIC_EXECUTION]: The tool supports 'Playbooks,' which are JSON-defined sequences of commands with variable substitution. The skill describes how these playbooks are automatically synthesized from session journals and subsequently executed, representing a runtime code generation and execution pattern.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 10:03 PM
Security Audit — agent-trust-hub — pp-plexctl