seoul-bike
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npxto download and run the@nomadamas/k-skillpackage. This package is a vendor-owned resource from 'nomadamas' used to manage skill instructions and execution stubs. - [COMMAND_EXECUTION]: The entry point for the skill involves executing a local Python script (
scripts/seoul_bike.py) through the vendor's CLI tool. This script handles the logic for querying and formatting station data. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external endpoints, creating a potential surface for indirect injection.
- Ingestion points: The
scripts/seoul_bike.pyfile fetches JSON data fromhttps://k-skill-proxy.nomadamas.orgusing theurlliblibrary. - Boundary markers: There are no explicit delimiters used in the instructions to wrap the external data fetched from the API.
- Capability inventory: The skill possesses network read capabilities and the ability to execute its own Python scripts via the vendor CLI.
- Sanitization: The script performs standard JSON parsing and URL encoding, but does not implement specific sanitization for the textual content returned by the API before it is presented to the agent.
- [DATA_EXFILTRATION]: Network operations are identified in
scripts/seoul_bike.py, which communicates withk-skill-proxy.nomadamas.org. These operations are directed to the vendor's own infrastructure to fetch public transit data and do not involve sensitive user information.
Audit Metadata