bok-ecos-stats

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation recommends running commands with npx which downloads the @nomadamas/k-skill package from the npm registry. \n- [REMOTE_CODE_EXECUTION]: The use of npx -y @nomadamas/k-skill@0 to fetch instructions and perform updates involves downloading and executing remote code from a vendor-controlled package. \n- [INDIRECT_PROMPT_INJECTION]: The skill ingests economic data from an external API. \n
  • Ingestion points: scripts/bok_ecos.py (via urllib.request). \n
  • Boundary markers: No specific delimiters or warning markers are present in the script's output. \n
  • Capability inventory: scripts/bok_ecos.py (network GET). \n
  • Sanitization: Content from the ECOS API is projected into JSON or text without sanitization, creating a surface for potential instructions embedded in the data source to be processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:50 AM
Security Audit — agent-trust-hub — bok-ecos-stats