lovable-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the official Lovable MCP server at https://mcp.lovable.dev. This is a well-known service related to the skill's primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project configuration files (.lovable-agent/config.json), source code, and deployment logs. It includes instructions to scan code for secrets and verify deployment states, which are standard operational tasks. Risks are mitigated by the explicit instruction to avoid exposing sensitive values.
  • [COMMAND_EXECUTION]: The skill involves executing deployment operations via MCP servers or browser automation. These are the core intended functions of the skill and include safety checks such as user confirmation for destructive migrations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 11:47 AM
Security Audit — agent-trust-hub — lovable-deploy