pp-ticketmaster

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the ticketmaster-pp-cli binary using go install and npx. These downloads target the author's repositories at github.com/mvanhorn/printing-press-library and the @mvanhorn/printing-press-library npm package.
  • [COMMAND_EXECUTION]: The skill operates by executing shell commands via the ticketmaster-pp-cli binary to interact with Ticketmaster services and manage local data.
  • [DATA_EXFILTRATION]: The skill includes a --deliver webhook:<url> feature that allows the output of any command to be sent to an arbitrary external URL. While a standard feature for data routing, it presents a potential vector for transmitting data outside the local environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingest external data from Ticketmaster API responses and utilizes a local 'learning store' (SQLite) and playbooks that influence future agent behavior.
  • Ingestion points: External data enters the context via API responses, the local data.db file, playbooks JSON files, and a teach.log journal.
  • Boundary markers: No specific delimiters or 'ignore' instructions are provided to the agent for handling the ingested data.
  • Capability inventory: The skill uses the Read Bash tool to execute shell commands and performs network operations through the binary.
  • Sanitization: The skill documentation advises a 'PII rule' for the agent to manually strip personal identifiers before teaching the store, but no automated sanitization is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:12 AM
Security Audit — agent-trust-hub — pp-ticketmaster