pp-synology

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs an installation of the synology-pp-cli via npx from the @mvanhorn/printing-press-library package. This is a vendor-owned package associated with the skill author.
  • [DATA_EXFILTRATION]: The CLI provides a --deliver webhook:<url> parameter which allows command results, potentially containing NAS system logs, user lists, or file metadata, to be transmitted to arbitrary network addresses.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-controlled queries through a 'learning loop' and 'recall' system.
  • Ingestion points: User queries are captured and processed by the recall, teach, and playbook subcommands described in SKILL.md.
  • Boundary markers: The skill contains detailed instructions to mitigate shell-level command injection by writing queries to temporary files and reading them into variables rather than direct interpolation.
  • Capability inventory: The skill has access to comprehensive NAS operations via the synology-pp-cli, including file system modifications (mkdir, rename, delete), storage health data, and system audit logs.
  • Sanitization: The skill includes instructions for the agent to strip personally identifiable information (PII) from queries before they are stored in the learning system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:54 AM
Security Audit — agent-trust-hub — pp-synology