korean-jangbu-for
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads an upstream repository from 'https://github.com/kimlawtech/korean-jangbu-for.git' during the installation process.
- [REMOTE_CODE_EXECUTION]: The 'SKILL.md' file instructs the agent to execute 'npx -y @nomadamas/k-skill@0 instruct korean-jangbu-for' to fetch its primary instructions, resulting in the execution of a remote NPM package from the author's organization.
- [REMOTE_CODE_EXECUTION]: The 'scripts/install.sh' script executes a secondary installation script ('bash ~/.claude/skills/korean-jangbu-for/upstream/scripts/install.sh') that is downloaded from the upstream repository at runtime.
- [COMMAND_EXECUTION]: The installation script performs numerous local file system operations, including directory removal ('rm -rf'), file synchronization ('rsync' or 'cp -a'), and permission modifications ('chmod +x') within the agent's skill directory.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as bank statements (CSV), receipts (images), and invoices (PDF). This creates a surface for indirect prompt injection where malicious instructions embedded in financial documents could attempt to override agent behavior.
- [DYNAMIC_EXECUTION]: The 'scripts/install.sh' script dynamically modifies existing 'SKILL.md' files on the local system by appending a 'Response policy' section at runtime.
Audit Metadata