korean-humanizer

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to execute npx -y @nomadamas/k-skill@0 instruct korean-humanizer in SKILL.md. This command downloads and runs code from the npm registry at runtime to load primary instructions.
  • [COMMAND_EXECUTION]: The skill uses shell commands for initialization and retrieving file listings, as seen in the SKILL.md bash blocks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided text for humanization, creating a surface for potential prompt injection. * Ingestion points: User input text provided for humanization (instruction.md). * Boundary markers: No explicit boundary markers or delimiters for untrusted input are mentioned. * Capability inventory: Shell command execution via npx (SKILL.md). * Sanitization: No sanitization or filtering of external content is described.
  • [EXTERNAL_DOWNLOADS]: The skill fetches instructions and helper files from the npm registry and references external GitHub repositories for instructions and research context (nomadamas/k-skill, epoko77-ai/im-not-ai).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:36 AM
Security Audit — agent-trust-hub — korean-humanizer