nhis-care-checkup-search

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the vendor-owned package @nomadamas/k-skill@0 via npx to retrieve up-to-date instructions and helper files.- [COMMAND_EXECUTION]: The skill workflow involves executing npx for setup and curl for querying institution data from the health service proxy.- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the NHIS API via a proxy (Ingestion: institution details in instruction.md). It mitigates risks through explicit safety boundaries (Markers: Hard rules prohibiting payments and medical judgments in SKILL.md) and possesses limited execution capabilities (Inventory: curl, npx).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:49 AM
Security Audit — agent-trust-hub — nhis-care-checkup-search