lov-optimize-tauri-backend

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides installation instructions using npx to add packages from the skill-publisher namespace. It also mentions a plugin marketplace for the lov-dev vendor.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute series of bash commands including rg (ripgrep), find, wc, and xargs to perform codebase analysis, line counting, and pattern matching within the user's project directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill's workflow depends on reading and analyzing internal project files (e.g., lib.rs, package.json, AGENTS.md). This creates a vulnerability surface where malicious instructions placed inside project files could theoretically influence the agent during the analysis phase.
  • [SAFE]: The code refactoring strategies (modularization, command consolidation) and development workflow improvements (no-watch mode) follow industry best practices for Tauri development and do not show signs of malicious intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:07 PM
Security Audit — agent-trust-hub — lov-optimize-tauri-backend