kr-whois-lookup
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to use
npxto download and run the@nomadamas/k-skillpackage from the npm registry for retrieving instructions and performing updates. - [REMOTE_CODE_EXECUTION]: The skill executes code from the vendor's npm package (
@nomadamas/k-skill) vianpxto provide dynamic instructions and management features. - [COMMAND_EXECUTION]: The skill uses the
curlutility to perform network requests to thek-skill-proxyAPI for domain and IP registration data. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: User-provided domain names, IP addresses, and AS numbers enter the agent context through query parameters (instruction.md).
- Boundary markers: The instructions include a normalization step to sanitize inputs (removing schemes/paths from URLs, validating IP formats) and use
--data-urlencodeto mitigate basic injection in shell commands. - Capability inventory: Uses
curlfor network requests andnpxfor package execution. - Sanitization: Input normalization and URL encoding are present to manage untrusted data processing.
Audit Metadata