skills/akillness/jeo-skills/hwp/Gen Agent Trust Hub

hwp

Fail

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill requires the agent to run npx -y @nomadamas/k-skill@0 instruct hwp as a mandatory first step to obtain operational instructions. This involves downloading and executing code from an external npm registry.\n- [EXTERNAL_DOWNLOADS]:\n
  • Downloads the kordoc package from the npm registry to enable document parsing functionality.\n
  • Fetches the pdfjs-dist library from the npm registry, a well-known package for document handling.\n- [DYNAMIC_EXECUTION]: Employs shell heredocs to pipe dynamically generated JavaScript code into the Node.js runtime for document comparison and form-field extraction.\n- [COMMAND_EXECUTION]: Frequently utilizes shell commands to execute the kordoc CLI for document processing and monitoring.\n- [INDIRECT_PROMPT_INJECTION]:\n
  • Ingestion points: The skill ingests data from external .hwp, .hwpx, and .hwpml document files for parsing (instruction.md).\n
  • Boundary markers: No explicit delimiters or safety warnings are provided to ensure the agent isolates parsed document content from instructions.\n
  • Capability inventory: The skill possesses filesystem read/write access via kordoc and shell execution capabilities via npx (SKILL.md, instruction.md).\n
  • Sanitization: There is no evidence of sanitization or validation of the document content before it is presented to the agent context.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 19, 2026, 03:05 AM
Security Audit — agent-trust-hub — hwp