pp-shodhganga

Warn

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the shodhganga-pp-cli and shodhganga-pp-mcp tools via npx and go install targeting the vendor's (mvanhorn) repositories on GitHub and NPM.\n- [COMMAND_EXECUTION]: The skill implements a 'Learning Loop' where the agent is instructed to execute 'playbooks' and 'trial commands' which are shell command sequences dynamically retrieved from a local SQLite database based on natural language matching.\n- [DATA_EXFILTRATION]: The tool provides a --deliver webhook:url flag to transmit data to arbitrary external endpoints and a feedback mechanism that can be configured via SHODHGANGA_FEEDBACK_ENDPOINT to auto-send local session data to a remote server.\n- [PROMPT_INJECTION]: The recall mechanism matching natural language to stored playbooks creates a vulnerability for indirect prompt injection, where external data (e.g., harvested thesis metadata) could manipulate the local database to alter subsequent agent command execution logic.\n- [CREDENTIALS_UNSAFE]: The skill manages a credentials.toml file for storing sensitive information and includes utility commands like shodhganga-pp-cli doctor for verifying the environment and secret storage locations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 09:18 AM
Security Audit — agent-trust-hub — pp-shodhganga