pp-ticketdata
Warn
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: The CLI includes an output delivery feature (
--deliver webhook:<url>) that enables the agent to POST command results to arbitrary external URLs. This provides a functional capability for data exfiltration if the agent is prompted to read sensitive local files and route the output to a remote server controlled by an attacker. - [DYNAMIC_EXECUTION]: The skill implements a self-capturing "learning loop" that journals agent actions and synthesizes them into "playbooks." These playbooks are stored in a local SQLite database and later replayed with slot substitution, meaning the agent executes dynamically generated command sequences based on historical data.
- [COMMAND_EXECUTION]: The skill's core functionality relies on the execution of a custom binary (
ticketdata-pp-cli) via theBashtool. It grants the agent broad capability to manage local databases, write to the file system (teach.log,feedback.jsonl), and interact with network endpoints. - [EXTERNAL_DOWNLOADS]: The documentation instructs users to install dependencies from the author's NPM and GitHub repositories (
@mvanhorn/printing-press-library). This involves remote script execution throughnpx -yand binary compilation viago install. While these resources are controlled by the skill's author, they represent an external code execution vector. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from a public ticket API and stores it locally for analysis and "learning." Because this external data influences the synthesis of playbooks and the results of the
recallcommand, it creates a surface where poisoned external data could influence the agent's future command execution. - Ingestion points: External TicketData API responses and the local SQLite
data.dbstore. - Boundary markers: No specific delimiters or "ignore instructions" wrappers are defined to separate untrusted external price data from the agent's command templates.
- Capability inventory: Full shell access via
Bash, management of local configuration/state files, and arbitrary network POST capabilities. - Sanitization: The skill provides manual guidance to strip PII before "teaching" the system, but lacks automated sanitization for data ingested from external APIs.
Audit Metadata