webtoon-harness

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches its core harness components and agent definitions from the revfactory/webtoon-harness and akillness/jeo-skills repositories on GitHub.- [COMMAND_EXECUTION]: The scripts/install.sh script executes standard shell commands including git clone, mkdir, cp, and npx to set up the local development environment and agent configurations.- [REMOTE_CODE_EXECUTION]: The installation workflow involves downloading and placing external agent logic and skill files into the agent's internal .claude/ directory, which expands the agent's operational capabilities.- [DATA_EXFILTRATION]: The research phase (Phase 2) utilizes the scrapling skill to perform network operations and ingest data from various webtoon platforms and audience comment sections for trend analysis.- [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection where untrusted data from the web research phase is processed by the scenario team to generate scripts. Evidence chain: 1. Ingestion points: scrapling web extraction (Phase 2); 2. Boundary markers: Absent; 3. Capability inventory: Bash, Agent spawning, and Write (SKILL.md); 4. Sanitization: Not explicitly defined in instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 01:51 PM
Security Audit — agent-trust-hub — webtoon-harness