Atlas / Skills / nomadamas / Delivery Tracking

Delivery TrackingCAUTION

skills/nomadamas/delivery-tracking

한국인을 위한 스킬 모음집 - 에이전트를 한국인으로

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
MIT
Stars
7,804
01

Overview

한국인을 위한 스킬 모음집 - 에이전트를 한국인으로

Read from source at commit 85a601e83556OBSERVED · 2026-10-07
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: delivery-tracking
description: Track CJ대한통운 and 우체국 parcels by invoice number with official carrier endpoints, and structure the workflow around a carrier adapter that can grow to more couriers later.
license: MIT
metadata:
  category: logistics
  locale: ko-KR
  phase: v1
---

# delivery-tracking

<!-- k-skill:cli-stub — generated by scripts/generate-skill-stubs.js; edit skill.json / instruction.md instead -->

## Get the full instructions (required first step)

Run this and follow its output as the primary instructions for this skill:

```bash
npx -y @nomadamas/k-skill@0 instruct delivery-tracking
```

The CLI detects the current runtime (Dolshoi vault/CloakBrowser vs generic) and prints only the applicable instructions, always up to date. Helper files bundled with the CLI are listed by:

```bash
npx -y @nomadamas/k-skill@0 files delivery-tracking
```

Keep the CLI and every coding-agent skill install current (including Vercel Agent Skills) with:

```bash
npx -y @nomadamas/k-skill@0 update
```

If `npx` is unavailable, install Node.js 18+ or follow https://github.com/NomaDamas/k-skill#readme, or read the source instructions at https://github.com/NomaDamas/k-skill/blob/main/delivery-tracking/instruction.md.

## Legal disclaimer (required)

This skill is not an official feature of, officially supported by, affiliated with, sponsored by, approved by, or developed in collaboration with any third-party trademark owner or service operator it identifies. Third-party names are used only to describe the skill's function, lookup target, or compatibility.

Any automated collection of publicly accessible information must be limited to personal, non-organizational lookup. Do not use this skill for systematic or bulk crawling, database building, access-control or block circumvention, or conduct that interferes with a third party's business or service.

Read the full Korean legal disclaimer, including the cited Korean Supreme Court precedents and statutory limits, before use:

```bash
npx -y @nomadamas/k-skill@0 read delivery-tracking references/DISCLAIMER.md
```

## Hard rules even without the CLI

- Never execute payment, message/email delivery, final submission, cancellation, or public posting without the user's explicit approval immediately beforehand.
- Never ask for, print, or store plaintext credentials in chat, files, or shell arguments.
- Never bypass legal, physical-presence, CAPTCHA, identity-proofing, or electronic-signature boundaries.
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

HIGHPrompt injection · review.instruction_override · CWE-94, CWE-1427
SKILL.md
Run this and follow its output as the primary instructions for this skill
Why it matters. The skill tells the agent to execute an external npx CLI command and treat its dynamically fetched output as the primary instructions, overriding the bundled SKILL.md content with whatever the remote tool returns at runtime.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 85a601e83556full audit observations/trust-audit/skill/nomadamas__delivery-tracking.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-0785a601e83556CAUTIONB89first audit
05

Questions

What does the Delivery Tracking skill do?

한국인을 위한 스킬 모음집 - 에이전트를 한국인으로

Is Delivery Tracking safe to install?

With care. The audit graded it B (89/100) and found 1 thing worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Delivery Tracking access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (85a601e83556), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement