hwp
Fail
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill requires the agent to run
npx -y @nomadamas/k-skill@0 instruct hwpas a mandatory first step to obtain operational instructions. This involves downloading and executing code from an external npm registry.\n- [EXTERNAL_DOWNLOADS]:\n - Downloads the
kordocpackage from the npm registry to enable document parsing functionality.\n - Fetches the
pdfjs-distlibrary from the npm registry, a well-known package for document handling.\n- [DYNAMIC_EXECUTION]: Employs shell heredocs to pipe dynamically generated JavaScript code into the Node.js runtime for document comparison and form-field extraction.\n- [COMMAND_EXECUTION]: Frequently utilizes shell commands to execute thekordocCLI for document processing and monitoring.\n- [INDIRECT_PROMPT_INJECTION]:\n - Ingestion points: The skill ingests data from external
.hwp,.hwpx, and.hwpmldocument files for parsing (instruction.md).\n - Boundary markers: No explicit delimiters or safety warnings are provided to ensure the agent isolates parsed document content from instructions.\n
- Capability inventory: The skill possesses filesystem read/write access via
kordocand shell execution capabilities vianpx(SKILL.md, instruction.md).\n - Sanitization: There is no evidence of sanitization or validation of the document content before it is presented to the agent context.
Recommendations
- AI detected serious security threats
Audit Metadata