s2b-notice-search

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the s2b-notice-search Node.js package. This package is identified as a vendor-specific resource corresponding to the skill's name and purpose.
  • [COMMAND_EXECUTION]: The skill uses browser automation frameworks (Aside Browser and BrowserOS CDP) to navigate the S2B website and interact with search forms. This is consistent with its stated purpose of web scraping and data retrieval.
  • [DATA_EXFILTRATION]: Network operations are directed towards the legitimate procurement domain www.s2b.kr. The instructions explicitly forbid performing login, payment, or contract-related actions, focusing solely on public notice lookup.
  • [PROMPT_INJECTION]: The skill parses HTML content from an external source (s2b.kr). While this creates a surface for indirect prompt injection if the source content were maliciously crafted, the risk is minimized by the skill's read-only scope and lack of persistent storage or high-privilege capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 10:19 AM
Security Audit — agent-trust-hub — s2b-notice-search