pp-rappi

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the rappi-pp-cli binary via npx from the official @mvanhorn/printing-press-library package or via go install from the author's GitHub repository github.com/mvanhorn/printing-press-library. These are standard installation methods from the vendor's own infrastructure.
  • [COMMAND_EXECUTION]: The skill is designed to execute the rappi-pp-cli binary to perform data retrieval and analysis tasks. It uses an --agent flag to ensure non-interactive, machine-readable output. The documentation explicitly states that the tool is read-only and should not be used for mutating actions like orders or payments.
  • [DATA_EXFILTRATION]: While the skill includes a --deliver webhook:<url> feature and a feedback mechanism (rappi-pp-cli feedback), the feedback is local-only by default, and the webhook sink is a user-controlled configuration for routing command output. No evidence of unauthorized data collection was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 06:58 PM
Security Audit — agent-trust-hub — pp-rappi