pp-synology
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill performs an installation of the
synology-pp-clivianpxfrom the@mvanhorn/printing-press-librarypackage. This is a vendor-owned package associated with the skill author. - [DATA_EXFILTRATION]: The CLI provides a
--deliver webhook:<url>parameter which allows command results, potentially containing NAS system logs, user lists, or file metadata, to be transmitted to arbitrary network addresses. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-controlled queries through a 'learning loop' and 'recall' system.
- Ingestion points: User queries are captured and processed by the
recall,teach, andplaybooksubcommands described inSKILL.md. - Boundary markers: The skill contains detailed instructions to mitigate shell-level command injection by writing queries to temporary files and reading them into variables rather than direct interpolation.
- Capability inventory: The skill has access to comprehensive NAS operations via the
synology-pp-cli, including file system modifications (mkdir, rename, delete), storage health data, and system audit logs. - Sanitization: The skill includes instructions for the agent to strip personally identifiable information (PII) from queries before they are stored in the learning system.
Audit Metadata