pp-weather-goat
Pass
Audited by Gen Agent Trust Hub on May 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and execute code from the author's npm package
@mvanhorn/printing-pressusingnpx. - [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the CLI tool and MCP server directly from the author's GitHub repository
github.com/mvanhorn/printing-press-libraryviago install. - [COMMAND_EXECUTION]: The skill relies on the execution of shell commands for installation, verification, and operation of the weather utility binary.
- [DATA_EXFILTRATION]: The CLI tool includes a
--deliverflag that enables the transmission of command output to arbitrary external webhook URLs. - [DATA_EXFILTRATION]: The
feedbackcommand supports sending local log data to a remote endpoint if theWEATHER_GOAT_FEEDBACK_ENDPOINTenvironment variable is set by the user or system.
Audit Metadata