Atlas / Skills / nomadamas / K Skill Setup

K Skill SetupSAFE

skills/nomadamas/k-skill-setup

한국인을 위한 스킬 모음집 - 에이전트를 한국인으로

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
—
Hosts
3 documented
License
MIT
Stars
7,804
01

Overview

한국인을 위한 스킬 모음집 - 에이전트를 한국인으로

Read from source at commit 85a601e83556OBSERVED · 2026-10-07
02

Install

Commands as the repository documents them. They are shown, not run.

npm install -g @nomadamas/k-skill@0
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
openclawmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: k-skill-setup
description: Install the k-skill bundle, use the unified CLI, resolve credentials, verify the runtime, and optionally configure update checks and GitHub starring.
license: MIT
metadata:
  category: setup
  locale: ko-KR
  phase: v1
---

# k-skill-setup

<!-- k-skill:cli-stub — generated by scripts/generate-skill-stubs.js; edit skill.json / instruction.md instead -->

## Get the full instructions (required first step)

Run this and follow its output as the primary instructions for this skill:

```bash
npx -y @nomadamas/k-skill@0 instruct k-skill-setup
```

The CLI detects the current runtime (Dolshoi vault/CloakBrowser vs generic) and prints only the applicable instructions, always up to date. Helper files bundled with the CLI are listed by:

```bash
npx -y @nomadamas/k-skill@0 files k-skill-setup
```

Keep the CLI and every coding-agent skill install current (including Vercel Agent Skills) with:

```bash
npx -y @nomadamas/k-skill@0 update
```

If `npx` is unavailable, install Node.js 18+ or follow https://github.com/NomaDamas/k-skill#readme, or read the source instructions at https://github.com/NomaDamas/k-skill/blob/main/k-skill-setup/instruction.md.

## Hard rules even without the CLI

- Never execute payment, message/email delivery, final submission, cancellation, or public posting without the user's explicit approval immediately beforehand.
- Never ask for, print, or store plaintext credentials in chat, files, or shell arguments.
- Never bypass legal, physical-presence, CAPTCHA, identity-proofing, or electronic-signature boundaries.
05

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 85a601e83556full audit observations/trust-audit/skill/nomadamas__k-skill-setup.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-0785a601e83556SAFEB89first audit
07

Questions

What does the K Skill Setup skill do?

한국인을 위한 스킬 모음집 - 에이전트를 한국인으로

Is K Skill Setup safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can K Skill Setup access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does K Skill Setup work with?

Its documentation mentions claude-code, codex and openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (85a601e83556), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement