building-register-search

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the vendor's CLI tool via npx to manage instructions and updates, which is the standard distribution method for the author's ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external APIs, creating a potential surface for indirect prompt injection. Evidence: 1. Ingestion points: Data is fetched from apis.data.go.kr and k-skill-proxy.nomadamas.org in scripts/building_register.py. 2. Boundary markers: The output does not use specific delimiters to wrap external data. 3. Capability inventory: The skill uses urllib.request for network operations and reads local configuration files. 4. Sanitization: Data is parsed from JSON and XML formats but does not undergo natural language sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:50 AM
Security Audit — agent-trust-hub — building-register-search