pp-robinhood

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the robinhood-pp-cli tool via npx from the @mvanhorn NPM scope and go install from the vendor's GitHub repository (github.com/mvanhorn/printing-press-library). These resources are associated with the identified vendor. \n- [COMMAND_EXECUTION]: The skill's primary functionality is derived from executing the robinhood-pp-cli binary to perform financial operations. It includes safety instructions for the agent, requiring explicit user approval and specific environment flags (ROBINHOOD_PP_ALLOW_WRITES=1) for live trade mutations. \n- [DATA_EXFILTRATION]: The CLI tool supports a --deliver webhook:<url> feature that can transmit command output to external URLs. While a documented feature for integration, it constitutes a potential network egress path for sensitive financial information.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 10:59 PM
Security Audit — agent-trust-hub — pp-robinhood