pp-trigger-dev
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the
trigger-dev-pp-clibinary usingnpx -yfrom the npm registry orgo installfrom GitHub. While these resources are associated with the skill's author (mvanhorn), they involve executing code downloaded from remote sources. - [DATA_EXFILTRATION]: The CLI features a
--deliver webhook:<url>flag, which allows the output of any command—including sensitive environment variable diffs, project metadata, and run payloads—to be POSTed to an external URL. This creates a significant data routing and exfiltration vector if the target URL is influenced by an attacker. - [COMMAND_EXECUTION]: The skill's primary function is to execute shell commands via the
trigger-dev-pp-clibinary to manage Trigger.dev resources. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Trigger.dev, such as error signatures and run payloads, which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Data is ingested through commands like
runs find,runs list, andfailures top(SKILL.md). - Capability inventory: The CLI can execute shell commands, write to the file system (
--deliver file:<path>), and perform network requests (--deliver webhook:<url>). - Boundary markers: The skill uses an
--agentflag to produce machine-readable JSON, but there are no instructions to sanitize or escape the content of the data before it is read by the agent. - Sanitization: No explicit sanitization or filtering of external content is mentioned.
Audit Metadata