lov-project-port
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied project names and feedback, creating an injection surface.\n
- Ingestion points: project name argument in scripts/hashport.sh; user instructions in the Feedback Loop section of SKILL.md.\n
- Boundary markers: Absent for project name input; procedural confirmation gate present for feedback processing.\n
- Capability inventory: Shell script execution and project file modification (.env, package.json).\n
- Sanitization: Character-by-character hashing in hashport.sh prevents command injection via the project name parameter.\n- [COMMAND_EXECUTION]: The skill executes a local bash script (scripts/hashport.sh) to compute ports and uses lsof to check availability. These operations are restricted to the local development environment and current working directory.
Audit Metadata