pp-quranku
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the quranku-pp-cli and quranku-pp-mcp binaries from the vendor's GitHub repository (github.com/mvanhorn/printing-press-library) and npm registry (@mvanhorn/printing-press-library).\n- [REMOTE_CODE_EXECUTION]: Installation instructions utilize go install and npx -y to download and execute code from the author's official software distributions.\n- [COMMAND_EXECUTION]: The skill operates by executing the quranku-pp-cli tool to interact with local databases and remote APIs for religious text retrieval and study tracking.\n- [DATA_EXFILTRATION]: The CLI includes a --deliver webhook flag that allows users to route command output to external URLs, and a feedback command that can optionally send logs to a configured remote endpoint.\n- [CREDENTIALS_UNSAFE]: The tool manages local configuration and secrets within a credentials.toml file and supports flexible directory management through environment variables like QURANKU_HOME.
Audit Metadata