lov-finder-action

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill generates Swift source code and AppleScript at runtime to create Finder extensions. It relies on NSAppleScript(source: script) within references/applescript-iterm.swift to execute dynamically constructed shell commands via AppleScript. Additionally, the workflow in SKILL.md involves using xcodegen and xcodebuild to compile and link generated Swift files into executable bundles.
  • [COMMAND_EXECUTION]: The skill executes multiple shell commands to perform its core functions, including xcodegen for project generation, xcodebuild for compilation, and pluginkit for system extension registration as documented in CHANGELOG.md and SKILL.md.
  • [PRIVILEGE_ESCALATION]: The skill documentation and templates describe techniques to bypass macOS sandbox restrictions. Specifically, CHANGELOG.md notes the addition of a 'helper app pattern to bypass sandbox restrictions' and the use of com.apple.security.temporary-exception.files.absolute-path.read-write entitlements in xcodegen-template.yml to grant the generated extensions broader file system access than the standard sandbox allows.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by ingesting data from shared user profiles and brand configurations.
  • Ingestion points: The skill reads from profile.json via scripts/profile_store.py and references references/user-profile.md and skill.yaml.
  • Boundary markers: SKILL.md specifies that the agent should 'explicitly parse current requests' and verify project files, but it lacks strict sanitization for all interpolated profile values.
  • Capability inventory: The skill can write to the file system, compile code, and register system extensions using pluginkit.
  • Sanitization: scripts/profile_store.py includes a blacklist (SENSITIVE_PARTS) to prevent the storage of secrets like tokens or passwords in the profile, providing a partial mitigation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:06 PM
Security Audit — agent-trust-hub — lov-finder-action