skills/lobehub/lobe-chat/cli/Gen Agent Trust Hub

cli

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The documentation provides instructions for executing the CLI using bun and lh for development and production tasks.
  • [CREDENTIALS_UNSAFE]: References the storage of encrypted authentication tokens in ~/.lobehub/credentials.json as part of the documented CLI architecture.
  • [EXTERNAL_DOWNLOADS]: Describes functional features of the CLI for downloading generated assets and installing skills from GitHub or remote URLs.
  • [DATA_EXFILTRATION]: Documents file management features including uploads to S3 via presigned URLs and local file system access for configuration storage.
  • [PROMPT_INJECTION]: The CLI's generation commands process user-supplied prompts, presenting a standard attack surface for indirect prompt injection common to AI-integrated tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 02:14 PM