lov-article-creator

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external research materials, web excerpts, and partner articles for processing. It implements several robust security and fidelity measures:
  • Ingestion points: Untrusted data enters the agent context during Step 1 ('Build the truth ledger') from source files and project notes.
  • Boundary markers: For article reposting, the skill enforces a 'frozen zone' using data-repost-source="true" and uses writing-review.json to track semantic review status.
  • Capability inventory: The skill executes local Python scripts for packaging and validation (scripts/), calls an external lov-illustrate tool, and writes to the local filesystem.
  • Sanitization: It uses scripts/audit_repost.py and scripts/validate_article_package.py to ensure that source text has not been modified using SHA-256 hashing and text normalization.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute several local Python scripts provided in the scripts/ directory to handle deterministic logic such as image processing (Pillow), YAML parsing, and file integrity checks. These scripts are strictly scoped to the article packaging task.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 03:51 AM
Security Audit — agent-trust-hub — lov-article-creator