subway-lost-property
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses the vendor's own CLI tool,
@nomadamas/k-skill, to fetch updated instructions and execute helper scripts. This is part of the intended functionality provided by the skill author. - [COMMAND_EXECUTION]: The helper script
scripts/subway_lost_property.pyusessubprocess.runto executecurlcommands. These commands are used solely to verify the reachability of official lost property websites (LOST112 and Seoul Metro). The script uses safe practices, such as list-based command construction, to prevent shell injection. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input to generate search queries.
- Ingestion points: User input for
station,item, andlineare ingested ininstruction.mdand passed to the Python script. - Boundary markers: The workflow explicitly instructs the agent to ask for minimum clues before proceeding and provides clear guidelines for manual fallback if automated checks fail.
- Capability inventory: The skill has the capability to execute
curlviasubprocess.runand generatecurlcommand strings for the user. - Sanitization: The Python script uses
shlex.quote()when generating the examplecurlcommand and employs list-based arguments forsubprocess.run, effectively mitigating command injection risks.
Audit Metadata