pp-tidycal

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the tidycal-pp-cli tool using npx from @mvanhorn/printing-press-library or via go install from github.com/mvanhorn/printing-press-library. These sources are owned by the skill's author context.- [COMMAND_EXECUTION]: The primary function of the skill is to execute the tidycal-pp-cli binary with various arguments to manage bookings, contacts, and account details.- [DATA_EXFILTRATION]: The CLI tool supports a --deliver webhook:<url> flag, which allows the agent to POST command output (containing potentially sensitive calendar or contact data) to an arbitrary external URL.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 07:25 PM
Security Audit — agent-trust-hub — pp-tidycal