lov-migrate-camera-media
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/camera_media.pyexecutes system commands such asdiskutilandioregto identify volumes and USB link speeds. Thescripts/check_media.pyscript usesffmpegandffprobefor media validation. All calls use list-based arguments to prevent command injection. - [INDIRECT_PROMPT_INJECTION]: The skill processes files from external camera media, which represents an attack surface for indirect prompt injection. However, the skill implements a
safe_relfunction to prevent path traversal and validates file metadata against a generated manifest before processing. - [EXTERNAL_DOWNLOADS]: The README mentions installation via
npx lovstudio, which involves downloading code from the vendor's namespace. This is a standard installation procedure for this vendor's tools.
Audit Metadata