pp-printgoat
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the installation of a CLI tool using
npx -y @mvanhorn/printing-press-library. This command fetches and executes code from the public npm registry. The package belongs to the vendor's own namespace. - [DATA_EXFILTRATION]: The CLI tool includes a
--deliver webhook:<url>capability. This allows command results, which may include sensitive model metadata or search history, to be transmitted to any external URL specified by the user or the agent's instructions. - [INDIRECT_PROMPT_INJECTION]: The skill implements a persistent 'Automatic learning' system (
recall,teach,playbook) that stores data from user queries and external search results. This stored data is used to synthesize playbooks that guide the agent's future logic and tool usage. Malicious content within 3D model listings from external sites (Printables, Thingiverse, Cults3D) could be ingested and stored, potentially influencing future agent actions. - Ingestion points: External search results and model metadata from 3D printing communities; user queries.
- Boundary markers: No specific delimiters or safety instructions are defined for the 'teach' process.
- Capability inventory: The tool allows bash execution, network search, and file system writes for model downloads.
- Sanitization: The system scans for PII in queries but provides warnings rather than blocking filters.
- [DYNAMIC_EXECUTION]: The 'playbook' system allows the storage and subsequent replay of shell command sequences (
steps) with variable substitution (slots). The agent is instructed to execute these stored command steps dynamically based on the results of therecalltool.
Audit Metadata