lov-integrate-lovinsp
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from local project configuration files and development server outputs to drive its logic.
- Ingestion points: Reads local configuration files (package.json, vite.config.ts, etc.) and captures responses from the local development server (127.0.0.1) via curl.
- Boundary markers: The skill does not employ explicit boundary markers when processing ingested project data.
- Capability inventory: Includes file system write access for configuration updates, package manager execution (npm/pnpm), and local network operations.
- Sanitization: Verification is performed using simple substring and regex matching (e.g., checking for the 'lovinspPlugin' identifier).
- [COMMAND_EXECUTION]: Utilizes system CLI tools for environment setup and runtime validation.
- Invokes package managers to install the vendor library and uninstall legacy tools.
- Executes curl commands to inspect files served by the local development server to verify integration.
- [EXTERNAL_DOWNLOADS]: Fetches required software components from standard package registries.
- Downloads and installs the 'lovinsp' package using pnpm or npm, which is a standard vendor-provided resource.
- [DYNAMIC_EXECUTION]: Automatically modifies application executable configurations at runtime.
- Generates and injects plugin initialization code into JavaScript and TypeScript configuration files for build tools like Vite and Webpack.
Audit Metadata