pp-ufo

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill facilitates the installation of the ufo-goat-pp-cli tool using go install from github.com/mvanhorn/printing-press-library and npx from the @mvanhorn/printing-press package. These resources are associated with the skill's specific vendor infrastructure and are used for functional setup.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The tool includes a --deliver webhook:<url> feature that allows data retrieved by the agent to be POSTed to arbitrary external URLs. It also supports a feedback command capable of transmitting local user notes to a remote endpoint if a specific environment variable is configured.
  • [COMMAND_EXECUTION]: The skill requires the Read Bash tool to execute shell commands for interacting with the CLI binary, passing user-provided arguments directly to the tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, community-maintained, or government-provided manifests and file data, which serves as a potential vector for indirect prompt injection.
  • Ingestion points: Data is fetched and processed via the sync, new, and files command groups.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious content within the UAP files or manifests.
  • Capability inventory: The agent has access to shell command execution, file writing (--deliver file), and network requests (--deliver webhook).
  • Sanitization: The skill does not describe any specific validation or sanitization routines for the ingested data before it is presented to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 01:34 PM
Security Audit — agent-trust-hub — pp-ufo