cheap-gas-nearby

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to run npx -y @nomadamas/k-skill@0, which downloads the vendor's package from the public npm registry.
  • [REMOTE_CODE_EXECUTION]: Executing the CLI tool via npx results in the dynamic retrieval and execution of code from the external npm repository to generate skill instructions.
  • [COMMAND_EXECUTION]: The SKILL.md file defines specific shell commands for the agent to execute to access instructions and helper files.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided location strings (neighborhoods, landmarks) which could potentially contain adversarial instructions.
  • Ingestion points: User location queries in instruction.md.
  • Boundary markers: The skill is instructed to explicitly ask the user for location before searching.
  • Capability inventory: Performs network requests via a vendor proxy to official fuel and map APIs.
  • Sanitization: No specific sanitization methods are documented for the incoming location strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:36 AM
Security Audit — agent-trust-hub — cheap-gas-nearby