assembly-bill-vote-search
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the user to execute command lines using
npx -y @nomadamas/k-skill@0. This pattern downloads and runs code from the NPM registry at runtime. The package is a resource owned by the skill author. - [EXTERNAL_DOWNLOADS]: The skill uses
curlto fetch legislative data fromk-skill-proxy.nomadamas.org. This domain belongs to the skill vendor. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the Korean National Assembly Open API, which represents an attack surface for indirect prompt injection.
- Ingestion points: The skill fetches content from the assembly's bill information and vote summary endpoints via a proxy described in
instruction.md. - Boundary markers: None explicitly defined for the API response processing.
- Capability inventory: The skill uses
curlfor network requests and shell execution for the CLI stub. - Sanitization: No explicit sanitization or validation of the API payload is described before the information is presented to the agent.
Audit Metadata