oma-hwp

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill converts HWP, HWPX, and HWPML documents into Markdown or JSON formats using the kordoc CLI tool executed via bunx.
  • [SAFE]: A local post-processing script, resources/flatten-tables.ts, is used to clean up the output by converting HTML tables to Github Flavored Markdown (GFM) and stripping Hancom-specific Private Use Area (PUA) characters. This script uses standard libraries (turndown and turndown-plugin-gfm) and performs no network operations.
  • [SAFE]: The skill includes comprehensive documentation for execution protocols, configuration, and troubleshooting, providing transparency into its operations and error-handling procedures.
  • [SAFE]: While the skill suggests a curl | bash command for installing the bun runtime in its documentation, this is presented as a manual recovery step for the user rather than an automated execution pattern.
  • [SAFE]: No evidence of prompt injection, data exfiltration, credential theft, or unauthorized persistence was found during the analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 06:54 AM
Security Audit — agent-trust-hub — oma-hwp