naver-ad-performance

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to fetch and run a CLI stub (@nomadamas/k-skill) from the official npm registry. This is used for retrieving instructions and executing the localized script. The vendor is identified as the author of the skill.
  • [COMMAND_EXECUTION]: Executes a Python script (scripts/naver_ad_performance.py) locally via the npx wrapper to interact with the Naver Search Ad API.
  • [SAFE]: The skill implements strict read-only boundaries. The Python script exclusively uses GET requests for specific reporting endpoints (/ncc/campaigns, /ncc/adgroups, /ncc/keywords, /stats, /keywordstool). It lacks any code for creating, updating, or deleting resources.
  • [SAFE]: Sensitive credentials (API Key, Secret, Customer ID) are retrieved from standard environment variables (NAVER_AD_API_KEY, etc.) and are never hardcoded or printed to logs. The skill provides clear error messages when these are missing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:49 AM
Security Audit — agent-trust-hub — naver-ad-performance