korean-patent-search
Warn
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's primary instructions in
SKILL.mddirect the agent to runnpx -y @nomadamas/k-skill@0. This command downloads external code from the NPM registry to provide dynamic instructions and helper files. - [REMOTE_CODE_EXECUTION]: The use of
npxto execute the@nomadamas/k-skillpackage constitutes remote code execution. This package is used to fetch instructions, list files, and execute the Python search script, meaning the skill's behavior is dependent on the content of a remote package. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from the KIPRIS Plus Open API, which contains user-contributed patent information such as titles and abstracts. This creates a surface where malicious instructions embedded in patent data could be processed by the agent.
- Ingestion points: Patent search results are fetched via
scripts/patent_search.pyfrom the KIPRIS API. - Boundary markers: The skill does not implement specific delimiters or instructions to ignore embedded commands in the patent data.
- Capability inventory: The skill includes network access via
urllib.requestand script execution via the CLI tool. - Sanitization: There is no evidence of sanitization or filtering of the text content retrieved from the API before it is passed to the agent.
Audit Metadata