pp-walkerplus

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download the walkerplus-pp-cli tool via NPM (@mvanhorn/printing-press-library) and Go (github.com/mvanhorn/printing-press-library). These resources are hosted on public registries and GitHub under the author's namespace.
  • [REMOTE_CODE_EXECUTION]: The skill contains commands to install and build executable code from remote sources using npx and go install. The agent is instructed to run these to set up the necessary environment for the skill.
  • [COMMAND_EXECUTION]: The skill operates by executing a local binary walkerplus-pp-cli with various flags and parameters to query event data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the Walkerplus website, which could potentially contain adversarial instructions.
  • Ingestion points: Data is fetched from external public HTML via the walkerplus-pp-cli tool during search, shortlist, and event operations.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are provided when processing the tool's output.
  • Capability inventory: The skill has access to shell command execution for the walkerplus-pp-cli binary.
  • Sanitization: No specific sanitization or validation of the scraped HTML content is described in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 11:58 AM
Security Audit — agent-trust-hub — pp-walkerplus