lov-app-generator

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates project creation and maintenance by executing standard shell commands. Evidence includes the use of 'pnpm' and 'npx' for package management, the execution of a bundled Python audit script ('scripts/audit_app_project.py'), and the use of 'tmux' to manage persistent background processes for Tauri development servers. It also performs local loopback network requests via 'curl' to verify module transformation outcomes.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it is designed to analyze existing codebases. Evidence chain: (1) Ingestion points: The skill reads 'package.json', build configurations, and project metadata through the 'audit_app_project.py' script. (2) Boundary markers: No specific delimiters are used to isolate project data from agent instructions. (3) Capability inventory: The skill has extensive filesystem write access and shell execution capabilities. (4) Sanitization: The audit process uses regex-based filtering and standard parsing for structured data formats like JSON and TOML. This is a standard risk profile for automated developer tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:05 PM
Security Audit — agent-trust-hub — lov-app-generator