hankookilbo-news
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions suggest running
npx -y @nomadamas/k-skill@0to fetch and display the latest instructions. The package resides in the author's own namespace (@nomadamas), representing a vendor-owned resource for managing skill lifecycle. - [COMMAND_EXECUTION]: The skill uses
curlto make POST requests to a remote news API and pipes the output into a short Python script for JSON parsing. The Python code is a standard one-liner (import json,sys; for i in json.load(sys.stdin)["result"]["structuredContent"]["items"]: print(...)) used solely for formatting metadata. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes external news data (titles and excerpts) from
https://mcp.hankookilbo.com/mcp. - Ingestion points: News metadata (titles, excerpts, and URLs) is retrieved via
curlas specified ininstruction.md. - Boundary markers: The skill includes instructions to strictly quote
item.titlewithout modification and use the[Title](URL)format to maintain data integrity. - Capability inventory: The skill uses
curlfor network access andpython3for parsing, but does not perform file writes or local execution based on the news content. - Sanitization: There is no active sanitization of the retrieved text; the skill relies on instructions for the agent to treat the metadata as literal citations.
Audit Metadata