pp-rapidapi
Warn
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill documents the
--deliver webhook:<url>flag, which enables the output of any command to be sent to an arbitrary external URL. This creates a significant risk of exfiltration for sensitive information retrieved by the CLI, such as account subscriptions, favorites, notifications, and workspace metadata. - [DYNAMIC_EXECUTION]: The skill implements a 'Playbook' system that retrieves and executes sequences of commands (
steps) from a local database. These steps are executed dynamically with slot substitutions ({slot}), introducing risks related to runtime command assembly and potential execution of malicious choreography. - [INDIRECT_PROMPT_INJECTION]: The skill features an autonomous 'learning loop' that processes untrusted marketplace data to derive future behavior.
- Ingestion points: Data from the RapidAPI marketplace is ingested via
syncandsearchcommands and stored in a local SQLite database. - Boundary markers: The instructions do not provide delimiters or safety warnings to ensure the agent ignores potential instructions embedded within marketplace metadata or API descriptions.
- Capability inventory: The skill is authorized to execute bash commands, perform network operations via GraphQL and webhooks, and manage local configuration and credentials.
- Sanitization: No sanitization or validation mechanisms are described for the marketplace content that is used to synthesize
playbook_candidatesorresultsin the learning store. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of external binaries from remote sources, specifically targeting the
github.com/mvanhorn/printing-press-libraryrepository and the@mvanhorn/printing-press-libraryNPM package. These resources are provided by the identified vendor.
Audit Metadata