pp-rapidapi

Warn

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill documents the --deliver webhook:<url> flag, which enables the output of any command to be sent to an arbitrary external URL. This creates a significant risk of exfiltration for sensitive information retrieved by the CLI, such as account subscriptions, favorites, notifications, and workspace metadata.
  • [DYNAMIC_EXECUTION]: The skill implements a 'Playbook' system that retrieves and executes sequences of commands (steps) from a local database. These steps are executed dynamically with slot substitutions ({slot}), introducing risks related to runtime command assembly and potential execution of malicious choreography.
  • [INDIRECT_PROMPT_INJECTION]: The skill features an autonomous 'learning loop' that processes untrusted marketplace data to derive future behavior.
  • Ingestion points: Data from the RapidAPI marketplace is ingested via sync and search commands and stored in a local SQLite database.
  • Boundary markers: The instructions do not provide delimiters or safety warnings to ensure the agent ignores potential instructions embedded within marketplace metadata or API descriptions.
  • Capability inventory: The skill is authorized to execute bash commands, perform network operations via GraphQL and webhooks, and manage local configuration and credentials.
  • Sanitization: No sanitization or validation mechanisms are described for the marketplace content that is used to synthesize playbook_candidates or results in the learning store.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of external binaries from remote sources, specifically targeting the github.com/mvanhorn/printing-press-library repository and the @mvanhorn/printing-press-library NPM package. These resources are provided by the identified vendor.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 13, 2026, 05:46 AM
Security Audit — agent-trust-hub — pp-rapidapi