lov-branding-consistency
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes Python scripts (
scripts/profile_store.py,scripts/copy_audit.py,scripts/sync_dependents.py) designed for local execution. These scripts perform metadata validation, text auditing using regular expressions, and management of user preferences. Their logic is transparent and focused on the skill's stated utility. - [DATA_EXPOSURE]: The
profile_store.pyscript manages user preferences in a local JSON profile. It incorporates a security filter (SENSITIVE_PARTS) that explicitly prevents keys containing strings like 'token', 'secret', 'password', or 'api_key' from being written to the persistent profile, mitigating the risk of credential leakage. - [PERSISTENCE]: The skill implements a persistence mechanism for user records and brand preferences by writing to a local configuration file (e.g.,
~/.config/agent-skills/profile.json). This is a legitimate use case for maintaining state across agent sessions and does not involve unauthorized modification of system startup scripts or scheduled tasks. - [INDIRECT_PROMPT_INJECTION]: As the skill is designed to process and rewrite user-provided text for branding purposes, it possesses an ingestion surface for indirect prompt injection. However, the skill implements a 'visibility firewall' and specific quality gates to separate user content from internal metadata, and its capabilities are limited to text processing and local configuration management, keeping the risk level low.
Audit Metadata