pp-webflow

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides a --deliver webhook:<url> flag which allows the tool to POST its output (including Webflow site metadata, CMS content, and audit findings) to any external URL. This capability presents a risk of data exfiltration if the agent is directed to use an untrusted endpoint.
  • [DYNAMIC_EXECUTION]: The skill utilizes a "playbook" system where sequences of shell commands are defined in JSON structures and executed at runtime with variable substitution. This allows for dynamic construction and execution of commands based on stored templates or local files.
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to install components from the vendor's infrastructure:
  • NPX installation of the @mvanhorn/printing-press-library package.
  • Go installation of the webflow-pp-cli and webflow-pp-mcp binaries from github.com/mvanhorn/printing-press-library.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection due to the way it processes external data:
  • Ingestion points: Data is ingested from the Webflow Data API (CMS items, pages, form submissions) and a local SQLite database (data.db) located at SKILL.md.
  • Boundary markers: The CLI uses JSON formatting for agent mode, but the skill lacks explicit instructions for the agent to ignore potentially malicious instructions embedded within the content retrieved from Webflow.
  • Capability inventory: The skill has the ability to write files (--deliver file), perform network POST requests (--deliver webhook), and modify remote CMS content (items bulk-set) as documented in SKILL.md.
  • Sanitization: The skill documentation mentions stripping PII from taught queries but does not describe formal validation or sanitization for data retrieved from the Webflow API.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 01:23 AM
Security Audit — agent-trust-hub — pp-webflow