pp-techtwitter

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of a CLI tool via npx from the @mvanhorn scope on the npm registry and via go install from github.com/mvanhorn/printing-press-library. These are legitimate distribution methods for the tool author.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of the techtwitter-pp-cli binary. This is the primary purpose of the skill and is restricted to the specific CLI tool defined in the metadata.
  • [DATA_EXFILTRATION]: While the CLI tool includes a --deliver flag that can POST data to a webhook, this is a documented feature for user-directed routing of command output and does not demonstrate automated or hidden data exfiltration. The skill author uses their own infrastructure for this functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 08:11 AM
Security Audit — agent-trust-hub — pp-techtwitter