pp-tenki

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install an external binary using npx -y @mvanhorn/printing-press-library and go install github.com/mvanhorn/printing-press-library/library/travel/tenki/cmd/tenki-pp-cli@latest. These resources are hosted on the npm registry and GitHub under the vendor's account.
  • [COMMAND_EXECUTION]: The skill relies on the execution of the tenki-pp-cli binary through the Bash tool to perform weather lookups and comparisons. Use of the tool is documented and restricted to the tenki-pp-cli command set.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The tenki-pp-cli tool fetches data by scraping public HTML from tenki.jp.
  • Boundary markers: The skill does not define specific delimiters or instructions to prevent the agent from following potential commands embedded in the fetched weather data.
  • Capability inventory: The skill uses the Bash tool to execute shell commands.
  • Sanitization: The skill uses the --agent flag to ensure the CLI returns structured JSON, which provides better data separation than raw text, though it does not explicitly sanitize the content of the weather reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 11:54 AM
Security Audit — agent-trust-hub — pp-tenki