g2b-sanctioned-supplier

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions suggest using npx to fetch the @nomadamas/k-skill CLI tool from the npm registry and provides a link to GitHub for documentation. These are standard developer tools and official vendor resources.
  • [COMMAND_EXECUTION]: The skill uses a Python script (scripts/g2b_sanctioned_supplier.py) to perform API requests and suggests executing it via the npx command for helper functions. The operations are limited to networking for data lookup.
  • [DATA_EXFILTRATION]: The script connects to https://k-skill-proxy.nomadamas.org to retrieve sanction information. This is a vendor-owned domain used for its intended purpose as a proxy to the Korean public data API. No transmission of sensitive user data (like credentials or local files) was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 08:22 AM
Security Audit — agent-trust-hub — g2b-sanctioned-supplier