pp-rakuten-travel

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to install the rakuten-travel-pp-cli tool using npx -y @mvanhorn/printing-press-library or go install github.com/mvanhorn/printing-press-library/.... These resources originate from the developer's infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes accommodation data retrieved from Rakuten Travel. 1. Ingestion points: External data enters the context via the hotels search, hotels show, and offers search commands. 2. Boundary markers: There are no explicit delimiters used to separate external web content from the agent's instructions. 3. Capability inventory: The skill is granted Read Bash tool access to execute CLI commands. 4. Sanitization: No specific mechanisms for sanitizing or escaping external web data were identified.
  • [DYNAMIC_EXECUTION]: The documentation provides steps for building the command-line tool from source using go build.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 11:57 AM
Security Audit — agent-trust-hub — pp-rakuten-travel