lov-env-management
Warn
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPERSISTENCEDATA_EXFILTRATIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [COMMAND_EXECUTION]: The main logic in
scripts/env_manager.pyexecutes various system commands usingsubprocess.runandos.execvpto manage secrets and environment state. - It calls the
securityCLI on macOS for Keychain interactions. - It invokes the
opCLI for 1Password secret resolution. - It uses
launchctl(macOS) andsystemctl(Linux) to modify user session environment variables. - [PERSISTENCE]: The skill implements persistent environment variable injection by modifying shell configuration files.
- The
sync_shellfunction inscripts/env_manager.pyidentifies or creates a zsh resource file (defaulting to~/.zshenv) and inserts a managed code block. - This block sources a generated script containing credential exports, ensuring they are active in all future shell sessions.
- [DATA_EXFILTRATION]: The skill contains a
probefeature that sends managed secrets to remote network endpoints. - The
probe_keyfunction inscripts/env_manager.pytakes a user-supplied URL and performs an HTTPS GET request, including the secret key in the request headers (e.g., as a Bearer token). - This functionality creates a risk where a malicious actor or an unsupervised agent could be directed to send sensitive keys to an attacker-controlled server.
- [DYNAMIC_EXECUTION]: The skill dynamically generates shell scripts based on its internal state and configures the system to execute them.
- The
sync_shellfunction writes a new.zshfile containingexportcommands for all active credentials. - This generated file is then automatically sourced via the modifications made to the user's shell profile.
- [PRIVILEGE_ESCALATION]: The skill attempts to influence the environment of the entire user session beyond the scope of the current process.
- The
sync_systemfunction utilizeslaunchctl setenvorsystemctl --user set-environmentto push managed variables into the user session manager, exposing them to other running applications.
Audit Metadata