g2b-sanctioned-supplier
What this skill does
Public data lookup via API for checking sanctioned suppliers in procurement systems
github/nomadamas - Insecure Configuration - 7.1k stars
Threat analysis
Skill info
pkg:github/NomaDamas/k-skill@44fbaca?skill=g2b-sanctioned-supplierAssessments (2)
Insecure Configuration
Insecure Configuration via local-llm-review
instruction.md
The skill relies on `KSKILL_PROXY_BASE_URL` and `DATA_GO_KR_API_KEY` environment variables, which could be misconfigured or exposed if not properly managed.Information Disclosure
Information Disclosure via local-llm-review
instruction.md
The skill provides detailed error messages (e.g., 'k-skill-proxy에 필요한 API 키가 설정되어 있지 않습니다') that could be useful to an attacker for troubleshooting or reconnaissance.Badge
Add the Anomity scan badge for g2b-sanctioned-supplier to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of g2b-sanctioned-supplier? Report an issue or request a rescan.




