pp-ticketmaster
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the
ticketmaster-pp-clibinary usinggo installandnpx. These downloads target the author's repositories atgithub.com/mvanhorn/printing-press-libraryand the@mvanhorn/printing-press-librarynpm package. - [COMMAND_EXECUTION]: The skill operates by executing shell commands via the
ticketmaster-pp-clibinary to interact with Ticketmaster services and manage local data. - [DATA_EXFILTRATION]: The skill includes a
--deliver webhook:<url>feature that allows the output of any command to be sent to an arbitrary external URL. While a standard feature for data routing, it presents a potential vector for transmitting data outside the local environment. - [INDIRECT_PROMPT_INJECTION]: The skill ingest external data from Ticketmaster API responses and utilizes a local 'learning store' (SQLite) and playbooks that influence future agent behavior.
- Ingestion points: External data enters the context via API responses, the local
data.dbfile,playbooksJSON files, and ateach.logjournal. - Boundary markers: No specific delimiters or 'ignore' instructions are provided to the agent for handling the ingested data.
- Capability inventory: The skill uses the
Read Bashtool to execute shell commands and performs network operations through the binary. - Sanitization: The skill documentation advises a 'PII rule' for the agent to manually strip personal identifiers before teaching the store, but no automated sanitization is implemented.
Audit Metadata