oma-hwp
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill converts HWP, HWPX, and HWPML documents into Markdown or JSON formats using the
kordocCLI tool executed viabunx. - [SAFE]: A local post-processing script,
resources/flatten-tables.ts, is used to clean up the output by converting HTML tables to Github Flavored Markdown (GFM) and stripping Hancom-specific Private Use Area (PUA) characters. This script uses standard libraries (turndownandturndown-plugin-gfm) and performs no network operations. - [SAFE]: The skill includes comprehensive documentation for execution protocols, configuration, and troubleshooting, providing transparency into its operations and error-handling procedures.
- [SAFE]: While the skill suggests a
curl | bashcommand for installing thebunruntime in its documentation, this is presented as a manual recovery step for the user rather than an automated execution pattern. - [SAFE]: No evidence of prompt injection, data exfiltration, credential theft, or unauthorized persistence was found during the analysis.
Audit Metadata