lov-ataru-indexing
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill focuses on local maintenance of the Ataru search index. It resolves the application binary from standard system paths (like /Applications) or the user's PATH, ensuring only legitimate local executables are invoked.
- [COMMAND_EXECUTION]: The script
scripts/ataru_index.pyusessubprocess.runto interact with the Ataru binary. The execution is handled securely by passing arguments as a list, which prevents shell injection vulnerabilities. - [DATA_EXPOSURE]: The
scripts/profile_store.pyutility manages a local configuration file for the skill. It includes a security filter that explicitly prohibits storing any keys containing sensitive terms such as 'token', 'secret', 'password', or 'api_key', ensuring that credentials are not accidentally persisted to the disk. - [INDIRECT_PROMPT_INJECTION]: The skill ingests structured JSON data produced by the local Ataru binary to report indexing status. This represents a controlled data flow from a specific local tool, which is a low-risk interaction pattern.
- [SAFE]: Persistence is limited to a local JSON profile used to cache the path of the Ataru binary to improve performance across sessions. It does not attempt to modify system startup scripts or gain persistence beyond simple configuration storage.
Audit Metadata