pp-ufo
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill facilitates the installation of the
ufo-goat-pp-clitool usinggo installfromgithub.com/mvanhorn/printing-press-libraryandnpxfrom the@mvanhorn/printing-presspackage. These resources are associated with the skill's specific vendor infrastructure and are used for functional setup. - [DATA_EXPOSURE_AND_EXFILTRATION]: The tool includes a
--deliver webhook:<url>feature that allows data retrieved by the agent to be POSTed to arbitrary external URLs. It also supports afeedbackcommand capable of transmitting local user notes to a remote endpoint if a specific environment variable is configured. - [COMMAND_EXECUTION]: The skill requires the
Read Bashtool to execute shell commands for interacting with the CLI binary, passing user-provided arguments directly to the tool. - [INDIRECT_PROMPT_INJECTION]: The skill processes external, community-maintained, or government-provided manifests and file data, which serves as a potential vector for indirect prompt injection.
- Ingestion points: Data is fetched and processed via the
sync,new, andfilescommand groups. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious content within the UAP files or manifests.
- Capability inventory: The agent has access to shell command execution, file writing (
--deliver file), and network requests (--deliver webhook). - Sanitization: The skill does not describe any specific validation or sanitization routines for the ingested data before it is presented to the agent context.
Audit Metadata