pp-seek
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted job listings and details from the SEEK API and incorporates user queries into a persistent local knowledge base via a 'learning loop' (commands such as
teach,recall, andplaybook amend). This creates an attack surface where external content could influence future agent behavior. - Ingestion points: Reads live job listings and descriptive content from au.seek.com.
- Boundary markers: The instructions do not define explicit delimiters or 'ignore' instructions for the agent when processing external results.
- Capability inventory: The skill allows for local file writing (
--deliver file), network transmission (--deliver webhook), and modification of the local knowledge base. - Sanitization: Relies on the agent's manual compliance with instructions to strip personal identifiers before teaching queries.
- [DATA_EXFILTRATION]: The skill provides an output delivery mechanism via the
--deliver webhook:<url>argument, which permits the agent to POST command results—including potentially sensitive job history or account data—to an external endpoint. - [COMMAND_EXECUTION]: The skill's primary functionality is delivered through a custom binary (
seek-pp-cli) which the agent is instructed to execute with various arguments. - [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install CLI and MCP components from the author's GitHub repository and via the
npxpackage runner.
Audit Metadata