olive-young-search

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill directs the agent to download and run the daiso package via npx and provides instructions to clone, build, and execute code from the third-party hmmhmmhm/daiso-mcp GitHub repository.
  • [EXTERNAL_DOWNLOADS]: External dependencies and dynamic instructions are fetched at runtime from npm (packages @nomadamas/k-skill and daiso) and GitHub.
  • [COMMAND_EXECUTION]: The skill relies on shell command execution (npx, npm, git, node) to manage its dependencies and interact with the search tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external API responses via the daiso CLI, which could potentially contain malicious instructions.
  • Ingestion points: Output from daiso get commands described in instruction.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content are used when processing CLI output.
  • Capability inventory: The agent has permissions to execute shell commands and file system operations as part of the tool workflow.
  • Sanitization: There is no evidence of validation or sanitization of the data retrieved from the external retail search endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:50 AM
Security Audit — agent-trust-hub — olive-young-search