skills/cjakma/k-skill/toss-securities/Gen Agent Trust Hub

toss-securities

Warn

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install a third-party CLI tool by tapping an external Homebrew repository: brew tap JungHoonGhae/tossinvest-cli.
  • [REMOTE_CODE_EXECUTION]: The skill installs and executes the tossctl binary downloaded from an unverified personal GitHub repository. This tool is granted access to the user's Toss Securities session and sensitive financial data.
  • [COMMAND_EXECUTION]: The skill performs multiple shell command executions to retrieve financial information, such as tossctl account summary, tossctl portfolio positions, and tossctl orders list.
  • [REMOTE_CODE_EXECUTION]: The skill uses a Node.js package wrapper toss-securities to programmatically interact with the financial data, introducing an additional dependency layer.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 12, 2026, 05:48 AM
Security Audit — agent-trust-hub — toss-securities