korean-scholarship-search
What this skill does
Search Korean scholarship announcements across official sources, extract eligibility criteria, and filter results by school, income band, student level, and organization type.
github/nomadamas - Insecure Data Handling - 7.1k stars
Threat analysis
Skill info
pkg:github/NomaDamas/k-skill@44fbaca?skill=korean-scholarship-searchAssessments (2)
Insecure Data Handling
Insecure Data Handling via local-llm-review
scripts/scholarship_filter.py
The script reads JSON input from --input or stdin, but there is no explicit validation or sanitization of the input data. This could allow for injection of malicious data if the input is not properly Insecure Code Practices
Insecure Code Practices via local-llm-review
scripts/test_scholarship_filter.py
The test script uses `subprocess.run` with `input=payload`, but there is no indication that the payload is sanitized or validated. This could be a risk if the payload is user-controlled and not properBadge
Add the Anomity scan badge for korean-scholarship-search to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of korean-scholarship-search? Report an issue or request a rescan.




