coupang-product-search
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches its primary operating instructions and legal disclaimers by downloading the
@nomadamas/k-skillpackage from the NPM registry. - [COMMAND_EXECUTION]: The skill relies on the execution of
npxshell commands to dynamically load instructions and reference documentation for the agent. - [INDIRECT_PROMPT_INJECTION]: The skill processes product data retrieved from the
k-skill-proxy.nomadamas.orgAPI, which represents a surface for indirect prompt injection if the external data contains malicious instructions. - Ingestion points: Product list and item details retrieved via
curlininstruction.md. - Boundary markers: The instructions do not specify any delimiters or safety warnings to ignore instructions that might be embedded in the product data (e.g., in product titles).
- Capability inventory: The skill has the capability to perform network requests (
curl) and execute automated e-commerce actions like carting and purchasing via browser navigation. - Sanitization: There is no explicit requirement for the agent to sanitize or validate the content of the API response fields before processing them.
Audit Metadata