gongsijiga-search
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npx -y @nomadamas/k-skill@0to fetch its primary instructions and update its components. These resources originate from the vendor's own package repository. - [COMMAND_EXECUTION]: The skill instructs the agent to run shell commands including
npm install gongsijiga-searchandnode -eto execute its core functionality. These are standard operations for a developer-oriented library. - [DYNAMIC_EXECUTION]: The lookup logic is executed via
node -e, which dynamically runs JavaScript code to invoke thelookupGongsijigafunction. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data.
- Ingestion points: User-supplied address strings and HTTP response data from the
realtyprice.krdomain. - Boundary markers: None explicitly defined in the provided instructions.
- Capability inventory: Subprocess execution via
npmandnode, and network access viacurlor HTTP libraries. - Sanitization: Not explicitly documented in the provided markdown instructions.
Audit Metadata