olive-young-search
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill directs the agent to download and run the
daisopackage vianpxand provides instructions to clone, build, and execute code from the third-partyhmmhmmhm/daiso-mcpGitHub repository. - [EXTERNAL_DOWNLOADS]: External dependencies and dynamic instructions are fetched at runtime from npm (packages
@nomadamas/k-skillanddaiso) and GitHub. - [COMMAND_EXECUTION]: The skill relies on shell command execution (
npx,npm,git,node) to manage its dependencies and interact with the search tools. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external API responses via the
daisoCLI, which could potentially contain malicious instructions. - Ingestion points: Output from
daiso getcommands described ininstruction.md. - Boundary markers: No explicit delimiters or instructions to ignore embedded content are used when processing CLI output.
- Capability inventory: The agent has permissions to execute shell commands and file system operations as part of the tool workflow.
- Sanitization: There is no evidence of validation or sanitization of the data retrieved from the external retail search endpoints.
Audit Metadata