parking-lot-search
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses the
npxpackage runner to download and execute the@nomadamas/k-skillpackage from the npm registry to retrieve updated instructions and helper files. - [REMOTE_CODE_EXECUTION]: The instructions direct the agent to execute shell commands via
npxto interface with the author's CLI tool (@nomadamas/k-skill). Theinstruction.mdfile also provides a Node.js code example that relies on theparking-lot-searchpackage. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external public API endpoints (Data.go.kr and Kakao Map) and user-supplied location strings, which could theoretically contain malicious instructions.
- Ingestion points: Location strings provided by users and structured data returned from the
api.data.go.krandplace-api.map.kakao.comendpoints (as specified ininstruction.md). - Boundary markers: The skill requires a "Mandatory first question" to confirm the user's location, acting as a human-in-the-loop check before data processing.
- Capability inventory: The skill environment supports Node.js execution and shell command invocation via
npx(as seen inSKILL.md). - Sanitization: The instructions do not specify explicit sanitization or schema validation for the data returned from external APIs.
Audit Metadata