pp-tabelog

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of a CLI tool using npx from @mvanhorn/printing-press-library and using go install from github.com/mvanhorn/printing-press-library. These resources are provided by the skill's author.
  • [COMMAND_EXECUTION]: The skill defines a workflow involving the execution of the tabelog-pp-cli tool with various flags to query restaurant data and manage lists.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes restaurant discovery data fetched from external sources through the CLI, which constitutes an ingestion surface for untrusted data.
  • Ingestion points: Standard output and structured JSON results from tabelog-pp-cli find and tabelog-pp-cli show commands.
  • Boundary markers: None explicitly defined in the skill instructions to delimit tool output from agent instructions.
  • Capability inventory: The skill is permitted to use the Read Bash tool to execute shell commands.
  • Sanitization: No specific sanitization or validation of the CLI output is described in the prompt logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 11:56 AM
Security Audit — agent-trust-hub — pp-tabelog