lov-project-port

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied project names and feedback, creating an injection surface.\n
  • Ingestion points: project name argument in scripts/hashport.sh; user instructions in the Feedback Loop section of SKILL.md.\n
  • Boundary markers: Absent for project name input; procedural confirmation gate present for feedback processing.\n
  • Capability inventory: Shell script execution and project file modification (.env, package.json).\n
  • Sanitization: Character-by-character hashing in hashport.sh prevents command injection via the project name parameter.\n- [COMMAND_EXECUTION]: The skill executes a local bash script (scripts/hashport.sh) to compute ports and uses lsof to check availability. These operations are restricted to the local development environment and current working directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:08 PM
Security Audit — agent-trust-hub — lov-project-port