lov-migrate-camera-media

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/camera_media.py executes system commands such as diskutil and ioreg to identify volumes and USB link speeds. The scripts/check_media.py script uses ffmpeg and ffprobe for media validation. All calls use list-based arguments to prevent command injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes files from external camera media, which represents an attack surface for indirect prompt injection. However, the skill implements a safe_rel function to prevent path traversal and validates file metadata against a generated manifest before processing.
  • [EXTERNAL_DOWNLOADS]: The README mentions installation via npx lovstudio, which involves downloading code from the vendor's namespace. This is a standard installation procedure for this vendor's tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 09:48 PM
Security Audit — agent-trust-hub — lov-migrate-camera-media