store-longevity-radar

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructions suggest running the @nomadamas/k-skill package via npx to fetch the latest instructions and helper files. The package is managed by the skill author.
  • [EXTERNAL_DOWNLOADS]: The script store_longevity_download.py downloads store data from the official South Korean government portal (data.go.kr) and a Cloudflare R2 mirror. The process includes SHA-256 integrity checks for the mirror fallback.
  • [COMMAND_EXECUTION]: The helper scripts use argparse to handle user-supplied parameters for filtering store data and calculating longevity matching.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes store data from external CSV files which are treated as untrusted input.
  • Ingestion points: Data ingested from government ZIP files and user-provided historical CSVs in scripts/store_longevity_radar.py.
  • Boundary markers: No explicit delimiter protection against instructions embedded in data fields.
  • Capability inventory: File system access for caching and writing results, and standard mathematical operations.
  • Sanitization: Relies on standard Python csv and json modules for parsing data fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 04:29 AM
Security Audit — agent-trust-hub — store-longevity-radar