data-building-ledger

Fail

Audited by Snyk on Aug 19, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). Both links point to an unvetted, personal GitHub repository and a Fly.app–hosted remote API connector (not an official vendor or package manager), making them potential vectors for untrusted code execution or data exfiltration.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). 본 스킬의 워크플로우는 Step 1에서 사용자가 제공한 주소를 find_region으로 코드(sigungu_code/bdong_code)로 변환한 뒤, 해당 코드에 대해 건축HUB(data.go.kr) API를 호출해 결과(필지/동 단위 건축물 대장·인허가)를 읽어 LLM이 해당 데이터를 처리합니다(단, 외부에서 임의 텍스트가 그대로 “읽히는” 형태라기보다 API 조회 결과가 입력으로 들어감).

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 19, 2026, 01:43 PM
Issues
2
Security Audit — snyk — data-building-ledger