korean-holiday-calendar

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to fetch and execute its own instruction generator from the official NPM registry under the author's namespace (@nomadamas/k-skill). This is standard behavior for this vendor's tools.
  • [COMMAND_EXECUTION]: The skill executes curl commands to fetch holiday data from the vendor's proxy service (k-skill-proxy.nomadamas.org). These operations are read-only and restricted to public calendar information.
  • [CREDENTIALS_UNSAFE]: The skill correctly identifies that sensitive API keys for the Korean government data portal should only be stored on the proxy server and explicitly warns against storing credentials in chat or shell arguments. No hardcoded secrets were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:49 AM
Security Audit — agent-trust-hub — korean-holiday-calendar