fsc-corporate-info
What this skill does
The skill is a legitimate tool for querying corporate information from a public API (data.go.kr) via a proxy. It retrieves basic corporate details like representative, establishment date, and industry
github/nomadamas - Insecure Dependency - 7.1k stars
Threat analysis
Skill info
pkg:github/NomaDamas/k-skill@44fbaca?skill=fsc-corporate-infoAssessments (2)
Insecure Dependency
Insecure Dependency via local-llm-review
scripts/fsc_corporate_info.py
The script uses `urllib` for making HTTP requests, which is not inherently insecure, but the lack of explicit input validation and sanitization could be a risk if the input is not properly controlled Hardcoded Values
Hardcoded Values via local-llm-review
scripts/fsc_corporate_info.py
The `DEFAULT_PROXY_BASE_URL` is hardcoded to `https://k-skill-proxy.nomadamas.org`, which could be a risk if the proxy is not trusted or if the URL changes.Badge
Add the Anomity scan badge for fsc-corporate-info to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of fsc-corporate-info? Report an issue or request a rescan.




