korean-middle-korean
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill's instructions in
SKILL.mdandinstruction.mddirect the agent to execute code usingnpx -y @nomadamas/k-skill@0. This command fetches and executes the vendor's CLI package from the npm registry. - [COMMAND_EXECUTION]: The utility script
scripts/korean_middle_korean.jsimplements a--fileargument that is passed directly tofs.readFileSync. This allows for the reading of arbitrary files from the local file system, providing a potential path for the agent to access sensitive files it has permissions for. - [EXTERNAL_DOWNLOADS]: The skill initiates downloads of external Node.js packages from the npm registry to support its execution environment via the
npxutility. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill ingests external data through the
--text,--stdin, and--fileparameters within thescripts/korean_middle_korean.jsscript. - Boundary markers: There are no explicit delimiters or instructions within the processing logic to prevent the agent from interpreting embedded instructions in the source text as valid commands.
- Capability inventory: The conversion script has file system access (
fs.readFileSync) and is executed within a shell context. - Sanitization: The script uses regex to protect certain structures like URLs and code spans during conversion but does not perform sanitization or validation to filter out potentially malicious prompt instructions from the input data.
Audit Metadata