lov-finder-action
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill generates Swift source code and AppleScript at runtime to create Finder extensions. It relies on
NSAppleScript(source: script)withinreferences/applescript-iterm.swiftto execute dynamically constructed shell commands via AppleScript. Additionally, the workflow inSKILL.mdinvolves usingxcodegenandxcodebuildto compile and link generated Swift files into executable bundles. - [COMMAND_EXECUTION]: The skill executes multiple shell commands to perform its core functions, including
xcodegenfor project generation,xcodebuildfor compilation, andpluginkitfor system extension registration as documented inCHANGELOG.mdandSKILL.md. - [PRIVILEGE_ESCALATION]: The skill documentation and templates describe techniques to bypass macOS sandbox restrictions. Specifically,
CHANGELOG.mdnotes the addition of a 'helper app pattern to bypass sandbox restrictions' and the use ofcom.apple.security.temporary-exception.files.absolute-path.read-writeentitlements inxcodegen-template.ymlto grant the generated extensions broader file system access than the standard sandbox allows. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by ingesting data from shared user profiles and brand configurations.
- Ingestion points: The skill reads from
profile.jsonviascripts/profile_store.pyand referencesreferences/user-profile.mdandskill.yaml. - Boundary markers:
SKILL.mdspecifies that the agent should 'explicitly parse current requests' and verify project files, but it lacks strict sanitization for all interpolated profile values. - Capability inventory: The skill can write to the file system, compile code, and register system extensions using
pluginkit. - Sanitization:
scripts/profile_store.pyincludes a blacklist (SENSITIVE_PARTS) to prevent the storage of secrets like tokens or passwords in the profile, providing a partial mitigation.
Audit Metadata