lov-media-publisher
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell commands to facilitate its core automation features.
- The
scripts/check_video.pyscript invokesffprobeviasubprocess.runto validate video metadata against platform constraints. - The
scripts/notify_user.pyscript calls system binaries includingosascript,afplay, andsayusingsubprocess.runandsubprocess.Popenfor macOS notifications and text-to-speech functionality. - [INDIRECT_PROMPT_INJECTION]: The skill maintains an attack surface for indirect prompt injection due to its interaction with and ingestion of content from external publishing platforms.
- Ingestion points: Text content such as video titles, descriptions, and user-edited tags are read from the DOM of WeChat Channels and Bilibili pages using
snapshotText()and browser automation. - Boundary markers: The instructions do not employ specific boundary markers or delimiters when processing content retrieved from platform pages.
- Capability inventory: The skill has access to command execution through its included Python scripts and wide-ranging browser automation capabilities.
- Sanitization: There is no explicit mechanism described for sanitizing or validating text read back from external websites before it is used to inform further agent actions.
Audit Metadata