keris-academic-search
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses the
npxcommand to download and run the author's utility package@nomadamas/k-skillfor displaying instructions and executing the helper script. - Evidence:
npx -y @nomadamas/k-skill@0 instruct keris-academic-searchinSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external API responses (academic metadata), which is a potential surface for indirect prompt injection attacks.
- Ingestion points:
scripts/keris_academic.py(fetches XML fromwww.riss.kr). - Boundary markers: None; search results are summarized as plain text or JSON.
- Capability inventory: The script can read a specific configuration file and perform network operations to the RISS API.
- Sanitization: Standard XML parsing is used to extract text, but no specific filtering for LLM instructions is applied.
Audit Metadata