lov-clean-mac
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/disk_optimizer.pyexecutes system commandsduandrsyncto inventory files and perform migrations. These operations are implemented using list-basedsubprocess.runcalls, which prevents command injection vulnerabilities by not invoking a shell. The commands are strictly used for their intended purpose of storage management. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local filesystem (directory names and file metadata) during the inventory and planning phases. While this creates a potential surface for indirect prompt injection, the risk is mitigated by the use of structured JSON for internal data exchange, mandatory manual review of the generated 'plan.json', and the requirement for explicit, hardcoded confirmation strings before any destructive actions occur.
- [SAFE]: The skill implements robust data protection policies, including a hardcoded list of sensitive directories that are excluded from cleanup or migration (e.g., '.git', 'Mail', 'Photos Library', and specific app recording workspaces). Destructive cleanup is restricted to specific temporary rollback paths ending in '.cleanup' within the Trash, and the script explicitly checks that deletion targets are authorized rebuildable artifacts. No network communication, credential harvesting, or obfuscated payloads were identified.
Audit Metadata