pp-substack-reader
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill implements an 'automatic learning loop' using the
recall,teach, andplaybookcommands. This system journals every CLI invocation and auto-synthesizes 'playbooks' (choreographed command steps) from the local session journal. The agent is specifically instructed to 'replay Playbook.steps in order' when a match is found during therecallphase, which constitutes dynamic generation and execution of commands based on locally persisted history. - [DATA_EXFILTRATION]: The CLI provides a
--deliverflag that supports awebhook:<url>sink. This allows the agent to POST command results and archived data to arbitrary external URLs. Furthermore, thefeedbackcommand can be configured via environment variables (SUBSTACK_READER_FEEDBACK_ENDPOINT) to transmit local log data to a remote server. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest, archive, and read external Substack publications. These publications are untrusted sources that could contain embedded instructions designed to manipulate the agent's behavior during processing.
- Ingestion points: Substack post bodies, titles, and subtitles are retrieved via
readandarchivecommands and presented to the agent. - Boundary markers: While the
--agentflag enforces JSON output, the skill does not define explicit delimiters or instructions to ignore commands within the ingested text content. - Capability inventory: The agent has access to file system writes (SQLite database, configuration files), network access (Substack API and webhooks), and the ability to execute dynamically synthesized CLI command sequences.
- Sanitization: The instructions do not specify sanitization or filtering of the content retrieved from Substack posts.
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of a CLI tool from a remote repository. It provides instructions to use
npx -y @mvanhorn/printing-press-libraryandgo install github.com/mvanhorn/printing-press-library/.... Both sources are associated with the skill's author ('mvanhorn'). - [COMMAND_EXECUTION]: The skill is entirely centered around driving the
substack-reader-pp-clibinary, including commands that allow arbitrary read-only SQL queries (sql) against the local database.
Audit Metadata