toss-investment

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to fetch its own instruction stubs and legal documents from the @nomadamas/k-skill package. This is a vendor-owned resource provided by the author 'nomadamas' for skill management and documentation display.
  • [COMMAND_EXECUTION]: Provides commands to display instructions and legal disclaimers. These commands are limited to the skill's own documentation and do not execute arbitrary shell code.
  • [CREDENTIALS_UNSAFE]: The skill explicitly instructs users to store credentials (TOSSINVEST_CLIENT_ID, TOSSINVEST_CLIENT_SECRET) in environment variables rather than hardcoding them, following standard security best practices. It also includes instructions for the helper to mask secrets in error logs.
  • [DATA_EXFILTRATION]: The skill documentation specifies that it connects directly to https://openapi.tossinvest.com and prohibits sending data to shared proxies or third-party hosts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:49 AM
Security Audit — agent-trust-hub — toss-investment