coupang-product-search

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches its primary operating instructions and legal disclaimers by downloading the @nomadamas/k-skill package from the NPM registry.
  • [COMMAND_EXECUTION]: The skill relies on the execution of npx shell commands to dynamically load instructions and reference documentation for the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes product data retrieved from the k-skill-proxy.nomadamas.org API, which represents a surface for indirect prompt injection if the external data contains malicious instructions.
  • Ingestion points: Product list and item details retrieved via curl in instruction.md.
  • Boundary markers: The instructions do not specify any delimiters or safety warnings to ignore instructions that might be embedded in the product data (e.g., in product titles).
  • Capability inventory: The skill has the capability to perform network requests (curl) and execute automated e-commerce actions like carting and purchasing via browser navigation.
  • Sanitization: There is no explicit requirement for the agent to sanitize or validate the content of the API response fields before processing them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — coupang-product-search