korean-patent-search

Warn

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's primary instructions in SKILL.md direct the agent to run npx -y @nomadamas/k-skill@0. This command downloads external code from the NPM registry to provide dynamic instructions and helper files.
  • [REMOTE_CODE_EXECUTION]: The use of npx to execute the @nomadamas/k-skill package constitutes remote code execution. This package is used to fetch instructions, list files, and execute the Python search script, meaning the skill's behavior is dependent on the content of a remote package.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the KIPRIS Plus Open API, which contains user-contributed patent information such as titles and abstracts. This creates a surface where malicious instructions embedded in patent data could be processed by the agent.
  • Ingestion points: Patent search results are fetched via scripts/patent_search.py from the KIPRIS API.
  • Boundary markers: The skill does not implement specific delimiters or instructions to ignore embedded commands in the patent data.
  • Capability inventory: The skill includes network access via urllib.request and script execution via the CLI tool.
  • Sanitization: There is no evidence of sanitization or filtering of the text content retrieved from the API before it is passed to the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 19, 2026, 03:04 AM
Security Audit — agent-trust-hub — korean-patent-search