skills/nomadamas/k-skill/seoul-bike/Gen Agent Trust Hub

seoul-bike

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to download and run the @nomadamas/k-skill package. This package is a vendor-owned resource from 'nomadamas' used to manage skill instructions and execution stubs.
  • [COMMAND_EXECUTION]: The entry point for the skill involves executing a local Python script (scripts/seoul_bike.py) through the vendor's CLI tool. This script handles the logic for querying and formatting station data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external endpoints, creating a potential surface for indirect injection.
  • Ingestion points: The scripts/seoul_bike.py file fetches JSON data from https://k-skill-proxy.nomadamas.org using the urllib library.
  • Boundary markers: There are no explicit delimiters used in the instructions to wrap the external data fetched from the API.
  • Capability inventory: The skill possesses network read capabilities and the ability to execute its own Python scripts via the vendor CLI.
  • Sanitization: The script performs standard JSON parsing and URL encoding, but does not implement specific sanitization for the textual content returned by the API before it is presented to the agent.
  • [DATA_EXFILTRATION]: Network operations are identified in scripts/seoul_bike.py, which communicates with k-skill-proxy.nomadamas.org. These operations are directed to the vendor's own infrastructure to fetch public transit data and do not involve sensitive user information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — seoul-bike