korean-humanizer
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to execute
npx -y @nomadamas/k-skill@0 instruct korean-humanizerin SKILL.md. This command downloads and runs code from the npm registry at runtime to load primary instructions. - [COMMAND_EXECUTION]: The skill uses shell commands for initialization and retrieving file listings, as seen in the SKILL.md bash blocks.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided text for humanization, creating a surface for potential prompt injection. * Ingestion points: User input text provided for humanization (instruction.md). * Boundary markers: No explicit boundary markers or delimiters for untrusted input are mentioned. * Capability inventory: Shell command execution via npx (SKILL.md). * Sanitization: No sanitization or filtering of external content is described.
- [EXTERNAL_DOWNLOADS]: The skill fetches instructions and helper files from the npm registry and references external GitHub repositories for instructions and research context (nomadamas/k-skill, epoko77-ai/im-not-ai).
Audit Metadata