lov-integrate-lovinsp

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from local project configuration files and development server outputs to drive its logic.
  • Ingestion points: Reads local configuration files (package.json, vite.config.ts, etc.) and captures responses from the local development server (127.0.0.1) via curl.
  • Boundary markers: The skill does not employ explicit boundary markers when processing ingested project data.
  • Capability inventory: Includes file system write access for configuration updates, package manager execution (npm/pnpm), and local network operations.
  • Sanitization: Verification is performed using simple substring and regex matching (e.g., checking for the 'lovinspPlugin' identifier).
  • [COMMAND_EXECUTION]: Utilizes system CLI tools for environment setup and runtime validation.
  • Invokes package managers to install the vendor library and uninstall legacy tools.
  • Executes curl commands to inspect files served by the local development server to verify integration.
  • [EXTERNAL_DOWNLOADS]: Fetches required software components from standard package registries.
  • Downloads and installs the 'lovinsp' package using pnpm or npm, which is a standard vendor-provided resource.
  • [DYNAMIC_EXECUTION]: Automatically modifies application executable configurations at runtime.
  • Generates and injects plugin initialization code into JavaScript and TypeScript configuration files for build tools like Vite and Webpack.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:07 PM
Security Audit — agent-trust-hub — lov-integrate-lovinsp