pp-world-bank

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the world-bank-pp-cli and associated MCP server from the author's GitHub repository (github.com/mvanhorn/printing-press-library) and via the NPX registry (@mvanhorn/printing-press-library). These are vendor-owned resources associated with the skill author.
  • [COMMAND_EXECUTION]: The skill executes the world-bank-pp-cli binary to perform indicator searches, data comparisons, and ranking operations on World Bank datasets.
  • [DATA_EXFILTRATION]: The CLI tool supports a --deliver webhook:<url> parameter, which allows the agent to transmit command results directly to a remote HTTP endpoint. Additionally, the feedback command can transmit data to a configured external endpoint if specific environment variables are set.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes large volumes of external data from the World Bank Open Data API, which could be leveraged for prompt injection if the upstream data source is compromised.
  • Ingestion points: Data observations, indicator metadata, and catalog searches processed from the World Bank API via world-bank-pp-cli (SKILL.md).
  • Boundary markers: None provided in the skill instructions.
  • Capability inventory: File system writes (--deliver file:<path>), arbitrary network POSTs (--deliver webhook:<url>), and specialized feedback transmissions.
  • Sanitization: None observed; the skill processes and presents raw or reformatted API responses directly to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 03:12 AM
Security Audit — agent-trust-hub — pp-world-bank