lov-env-management

Warn

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPERSISTENCEDATA_EXFILTRATIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [COMMAND_EXECUTION]: The main logic in scripts/env_manager.py executes various system commands using subprocess.run and os.execvp to manage secrets and environment state.
  • It calls the security CLI on macOS for Keychain interactions.
  • It invokes the op CLI for 1Password secret resolution.
  • It uses launchctl (macOS) and systemctl (Linux) to modify user session environment variables.
  • [PERSISTENCE]: The skill implements persistent environment variable injection by modifying shell configuration files.
  • The sync_shell function in scripts/env_manager.py identifies or creates a zsh resource file (defaulting to ~/.zshenv) and inserts a managed code block.
  • This block sources a generated script containing credential exports, ensuring they are active in all future shell sessions.
  • [DATA_EXFILTRATION]: The skill contains a probe feature that sends managed secrets to remote network endpoints.
  • The probe_key function in scripts/env_manager.py takes a user-supplied URL and performs an HTTPS GET request, including the secret key in the request headers (e.g., as a Bearer token).
  • This functionality creates a risk where a malicious actor or an unsupervised agent could be directed to send sensitive keys to an attacker-controlled server.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates shell scripts based on its internal state and configures the system to execute them.
  • The sync_shell function writes a new .zsh file containing export commands for all active credentials.
  • This generated file is then automatically sourced via the modifications made to the user's shell profile.
  • [PRIVILEGE_ESCALATION]: The skill attempts to influence the environment of the entire user session beyond the scope of the current process.
  • The sync_system function utilizes launchctl setenv or systemctl --user set-environment to push managed variables into the user session manager, exposing them to other running applications.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 7, 2026, 10:06 PM
Security Audit — agent-trust-hub — lov-env-management