s2b-notice-search
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the
s2b-notice-searchNode.js package. This package is identified as a vendor-specific resource corresponding to the skill's name and purpose. - [COMMAND_EXECUTION]: The skill uses browser automation frameworks (Aside Browser and BrowserOS CDP) to navigate the S2B website and interact with search forms. This is consistent with its stated purpose of web scraping and data retrieval.
- [DATA_EXFILTRATION]: Network operations are directed towards the legitimate procurement domain
www.s2b.kr. The instructions explicitly forbid performing login, payment, or contract-related actions, focusing solely on public notice lookup. - [PROMPT_INJECTION]: The skill parses HTML content from an external source (
s2b.kr). While this creates a surface for indirect prompt injection if the source content were maliciously crafted, the risk is minimized by the skill's read-only scope and lack of persistent storage or high-privilege capabilities.
Audit Metadata