korean-heritage-search
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npxto download and execute the@nomadamas/k-skillpackage. This is a vendor-owned resource used to provide updated instructions and execute helper scripts. - [COMMAND_EXECUTION]: The skill instructs the agent to run shell commands using
npxto execute the bundled Python search script (scripts/korean_heritage_search.py). - [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process data from the Korea Heritage Service Open API, which could potentially contain malicious instructions embedded in heritage descriptions or event details.
- Ingestion points: The script
scripts/korean_heritage_search.pyfetches XML data fromhttps://www.khs.go.krvia its search and detail endpoints. - Boundary markers: The instructions do not specify explicit delimiters (e.g., XML tags or special markers) to isolate external data from the agent's core instructions when summarized.
- Capability inventory: The skill possesses network capabilities (via Python's
urllib) and the ability to execute local scripts through the CLI. - Sanitization: The Python script includes a
_clean_textutility that uses regular expressions to strip HTML tags and unescape entities, reducing the risk of markup-based injection.
Audit Metadata