store-longevity-radar
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructions suggest running the
@nomadamas/k-skillpackage vianpxto fetch the latest instructions and helper files. The package is managed by the skill author. - [EXTERNAL_DOWNLOADS]: The script
store_longevity_download.pydownloads store data from the official South Korean government portal (data.go.kr) and a Cloudflare R2 mirror. The process includes SHA-256 integrity checks for the mirror fallback. - [COMMAND_EXECUTION]: The helper scripts use
argparseto handle user-supplied parameters for filtering store data and calculating longevity matching. - [INDIRECT_PROMPT_INJECTION]: The skill processes store data from external CSV files which are treated as untrusted input.
- Ingestion points: Data ingested from government ZIP files and user-provided historical CSVs in
scripts/store_longevity_radar.py. - Boundary markers: No explicit delimiter protection against instructions embedded in data fields.
- Capability inventory: File system access for caching and writing results, and standard mathematical operations.
- Sanitization: Relies on standard Python
csvandjsonmodules for parsing data fields.
Audit Metadata