assembly-bill-vote-search

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the user to execute command lines using npx -y @nomadamas/k-skill@0. This pattern downloads and runs code from the NPM registry at runtime. The package is a resource owned by the skill author.
  • [EXTERNAL_DOWNLOADS]: The skill uses curl to fetch legislative data from k-skill-proxy.nomadamas.org. This domain belongs to the skill vendor.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the Korean National Assembly Open API, which represents an attack surface for indirect prompt injection.
  • Ingestion points: The skill fetches content from the assembly's bill information and vote summary endpoints via a proxy described in instruction.md.
  • Boundary markers: None explicitly defined for the API response processing.
  • Capability inventory: The skill uses curl for network requests and shell execution for the CLI stub.
  • Sanitization: No explicit sanitization or validation of the API payload is described before the information is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:49 AM
Security Audit — agent-trust-hub — assembly-bill-vote-search