pp-trigger-dev

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the trigger-dev-pp-cli binary using npx -y from the npm registry or go install from GitHub. While these resources are associated with the skill's author (mvanhorn), they involve executing code downloaded from remote sources.
  • [DATA_EXFILTRATION]: The CLI features a --deliver webhook:<url> flag, which allows the output of any command—including sensitive environment variable diffs, project metadata, and run payloads—to be POSTed to an external URL. This creates a significant data routing and exfiltration vector if the target URL is influenced by an attacker.
  • [COMMAND_EXECUTION]: The skill's primary function is to execute shell commands via the trigger-dev-pp-cli binary to manage Trigger.dev resources.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Trigger.dev, such as error signatures and run payloads, which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Data is ingested through commands like runs find, runs list, and failures top (SKILL.md).
  • Capability inventory: The CLI can execute shell commands, write to the file system (--deliver file:<path>), and perform network requests (--deliver webhook:<url>).
  • Boundary markers: The skill uses an --agent flag to produce machine-readable JSON, but there are no instructions to sanitize or escape the content of the data before it is read by the agent.
  • Sanitization: No explicit sanitization or filtering of external content is mentioned.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 02:02 PM
Security Audit — agent-trust-hub — pp-trigger-dev