lov-cli2anything

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes subprocess.run and node:child_process.spawn to manage its internal runtime, automate testing with npm, and launch the system browser for the Swagger UI preview. These operations are local and support the primary functionality.
  • [DYNAMIC_EXECUTION]: The tool generates JavaScript SDK source files and CLI entry points based on observed API patterns. It writes these files to the local project directory and applies appropriate file permissions (chmod) to generated binaries. This is the core task of the skill.
  • [EXTERNAL_DOWNLOADS]: Fetches public JavaScript assets from cdn.marmot-cloud.com for static analysis to discover API endpoints. It also retrieves plugin information from api.dshfind.com. These are legitimate data sources for the skill's discovery engine.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external API metadata and frontend code. While this represents a data ingestion surface, the risk is minimized as the data is analyzed for structural patterns to build static contracts (OpenAPI) rather than being executed or used to override agent instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:05 PM
Security Audit — agent-trust-hub — lov-cli2anything