lov-npm-publisher
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
gitandnpmCLI tools viasubprocess.runinscripts/publish.py. These operations are used for auditing local repository state and performing verified publishing. Inputs such as workflow paths are strictly validated byvalidate_workflow_pathto ensure they remain within the.github/workflowsdirectory and use approved file extensions. - [EXTERNAL_DOWNLOADS]: The script
scripts/publish.pyfetches metadata from the official npm registry (registry.npmjs.org) usingurllib.request. This operation is limited to reading public package information for version verification purposes and targets a well-known service. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from
package.jsonand git metadata. While this is an ingestion surface for untrusted data, the implementation uses structured parsing and validation to mitigate the risk of malicious instructions being processed as agent commands. - [SAFE]: The skill implements security best practices for secret management. The
scripts/profile_store.pyscript implements a blocklist for sensitive keys (e.g., 'token', 'secret', 'password') to prevent credentials from being stored in the user profile. Additionally, the profile store uses atomic writes and restricted filesystem permissions (0o600) to protect local data.
Audit Metadata