pp-tenki
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install an external binary using
npx -y @mvanhorn/printing-press-libraryandgo install github.com/mvanhorn/printing-press-library/library/travel/tenki/cmd/tenki-pp-cli@latest. These resources are hosted on the npm registry and GitHub under the vendor's account. - [COMMAND_EXECUTION]: The skill relies on the execution of the
tenki-pp-clibinary through theBashtool to perform weather lookups and comparisons. Use of the tool is documented and restricted to thetenki-pp-clicommand set. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The
tenki-pp-clitool fetches data by scraping public HTML fromtenki.jp. - Boundary markers: The skill does not define specific delimiters or instructions to prevent the agent from following potential commands embedded in the fetched weather data.
- Capability inventory: The skill uses the
Bashtool to execute shell commands. - Sanitization: The skill uses the
--agentflag to ensure the CLI returns structured JSON, which provides better data separation than raw text, though it does not explicitly sanitize the content of the weather reports.
Audit Metadata