kr-whois-lookup

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to use npx to download and run the @nomadamas/k-skill package from the npm registry for retrieving instructions and performing updates.
  • [REMOTE_CODE_EXECUTION]: The skill executes code from the vendor's npm package (@nomadamas/k-skill) via npx to provide dynamic instructions and management features.
  • [COMMAND_EXECUTION]: The skill uses the curl utility to perform network requests to the k-skill-proxy API for domain and IP registration data.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: User-provided domain names, IP addresses, and AS numbers enter the agent context through query parameters (instruction.md).
  • Boundary markers: The instructions include a normalization step to sanitize inputs (removing schemes/paths from URLs, validating IP formats) and use --data-urlencode to mitigate basic injection in shell commands.
  • Capability inventory: Uses curl for network requests and npx for package execution.
  • Sanitization: Input normalization and URL encoding are present to manage untrusted data processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:50 AM
Security Audit — agent-trust-hub — kr-whois-lookup