lov-npm-publisher

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes git and npm CLI tools via subprocess.run in scripts/publish.py. These operations are used for auditing local repository state and performing verified publishing. Inputs such as workflow paths are strictly validated by validate_workflow_path to ensure they remain within the .github/workflows directory and use approved file extensions.
  • [EXTERNAL_DOWNLOADS]: The script scripts/publish.py fetches metadata from the official npm registry (registry.npmjs.org) using urllib.request. This operation is limited to reading public package information for version verification purposes and targets a well-known service.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from package.json and git metadata. While this is an ingestion surface for untrusted data, the implementation uses structured parsing and validation to mitigate the risk of malicious instructions being processed as agent commands.
  • [SAFE]: The skill implements security best practices for secret management. The scripts/profile_store.py script implements a blocklist for sensitive keys (e.g., 'token', 'secret', 'password') to prevent credentials from being stored in the user profile. Additionally, the profile store uses atomic writes and restricted filesystem permissions (0o600) to protect local data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:07 PM
Security Audit — agent-trust-hub — lov-npm-publisher