korean-middle-korean

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill's instructions in SKILL.md and instruction.md direct the agent to execute code using npx -y @nomadamas/k-skill@0. This command fetches and executes the vendor's CLI package from the npm registry.
  • [COMMAND_EXECUTION]: The utility script scripts/korean_middle_korean.js implements a --file argument that is passed directly to fs.readFileSync. This allows for the reading of arbitrary files from the local file system, providing a potential path for the agent to access sensitive files it has permissions for.
  • [EXTERNAL_DOWNLOADS]: The skill initiates downloads of external Node.js packages from the npm registry to support its execution environment via the npx utility.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill ingests external data through the --text, --stdin, and --file parameters within the scripts/korean_middle_korean.js script.
  • Boundary markers: There are no explicit delimiters or instructions within the processing logic to prevent the agent from interpreting embedded instructions in the source text as valid commands.
  • Capability inventory: The conversion script has file system access (fs.readFileSync) and is executed within a shell context.
  • Sanitization: The script uses regex to protect certain structures like URLs and code spans during conversion but does not perform sanitization or validation to filter out potentially malicious prompt instructions from the input data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 07:50 AM
Security Audit — agent-trust-hub — korean-middle-korean