pp-tabelog
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of a CLI tool using npx from
@mvanhorn/printing-press-libraryand using go install fromgithub.com/mvanhorn/printing-press-library. These resources are provided by the skill's author. - [COMMAND_EXECUTION]: The skill defines a workflow involving the execution of the
tabelog-pp-clitool with various flags to query restaurant data and manage lists. - [INDIRECT_PROMPT_INJECTION]: The skill processes restaurant discovery data fetched from external sources through the CLI, which constitutes an ingestion surface for untrusted data.
- Ingestion points: Standard output and structured JSON results from
tabelog-pp-cli findandtabelog-pp-cli showcommands. - Boundary markers: None explicitly defined in the skill instructions to delimit tool output from agent instructions.
- Capability inventory: The skill is permitted to use the
Read Bashtool to execute shell commands. - Sanitization: No specific sanitization or validation of the CLI output is described in the prompt logic.
Audit Metadata