pp-seek

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted job listings and details from the SEEK API and incorporates user queries into a persistent local knowledge base via a 'learning loop' (commands such as teach, recall, and playbook amend). This creates an attack surface where external content could influence future agent behavior.
  • Ingestion points: Reads live job listings and descriptive content from au.seek.com.
  • Boundary markers: The instructions do not define explicit delimiters or 'ignore' instructions for the agent when processing external results.
  • Capability inventory: The skill allows for local file writing (--deliver file), network transmission (--deliver webhook), and modification of the local knowledge base.
  • Sanitization: Relies on the agent's manual compliance with instructions to strip personal identifiers before teaching queries.
  • [DATA_EXFILTRATION]: The skill provides an output delivery mechanism via the --deliver webhook:<url> argument, which permits the agent to POST command results—including potentially sensitive job history or account data—to an external endpoint.
  • [COMMAND_EXECUTION]: The skill's primary functionality is delivered through a custom binary (seek-pp-cli) which the agent is instructed to execute with various arguments.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install CLI and MCP components from the author's GitHub repository and via the npx package runner.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 10:24 PM
Security Audit — agent-trust-hub — pp-seek