subway-lost-property

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses the vendor's own CLI tool, @nomadamas/k-skill, to fetch updated instructions and execute helper scripts. This is part of the intended functionality provided by the skill author.
  • [COMMAND_EXECUTION]: The helper script scripts/subway_lost_property.py uses subprocess.run to execute curl commands. These commands are used solely to verify the reachability of official lost property websites (LOST112 and Seoul Metro). The script uses safe practices, such as list-based command construction, to prevent shell injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input to generate search queries.
  • Ingestion points: User input for station, item, and line are ingested in instruction.md and passed to the Python script.
  • Boundary markers: The workflow explicitly instructs the agent to ask for minimum clues before proceeding and provides clear guidelines for manual fallback if automated checks fail.
  • Capability inventory: The skill has the capability to execute curl via subprocess.run and generate curl command strings for the user.
  • Sanitization: The Python script uses shlex.quote() when generating the example curl command and employs list-based arguments for subprocess.run, effectively mitigating command injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:49 AM
Security Audit — agent-trust-hub — subway-lost-property