pp-ticketdata

Warn

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: The CLI includes an output delivery feature (--deliver webhook:<url>) that enables the agent to POST command results to arbitrary external URLs. This provides a functional capability for data exfiltration if the agent is prompted to read sensitive local files and route the output to a remote server controlled by an attacker.
  • [DYNAMIC_EXECUTION]: The skill implements a self-capturing "learning loop" that journals agent actions and synthesizes them into "playbooks." These playbooks are stored in a local SQLite database and later replayed with slot substitution, meaning the agent executes dynamically generated command sequences based on historical data.
  • [COMMAND_EXECUTION]: The skill's core functionality relies on the execution of a custom binary (ticketdata-pp-cli) via the Bash tool. It grants the agent broad capability to manage local databases, write to the file system (teach.log, feedback.jsonl), and interact with network endpoints.
  • [EXTERNAL_DOWNLOADS]: The documentation instructs users to install dependencies from the author's NPM and GitHub repositories (@mvanhorn/printing-press-library). This involves remote script execution through npx -y and binary compilation via go install. While these resources are controlled by the skill's author, they represent an external code execution vector.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from a public ticket API and stores it locally for analysis and "learning." Because this external data influences the synthesis of playbooks and the results of the recall command, it creates a surface where poisoned external data could influence the agent's future command execution.
  • Ingestion points: External TicketData API responses and the local SQLite data.db store.
  • Boundary markers: No specific delimiters or "ignore instructions" wrappers are defined to separate untrusted external price data from the agent's command templates.
  • Capability inventory: Full shell access via Bash, management of local configuration/state files, and arbitrary network POST capabilities.
  • Sanitization: The skill provides manual guidance to strip PII before "teaching" the system, but lacks automated sanitization for data ingested from external APIs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 04:01 PM
Security Audit — agent-trust-hub — pp-ticketdata