lov-search-chat

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/ataru_recall.py discovers and executes a local binary (typically ataru or lovcode) using the subprocess module to perform searches and read transcripts.
  • The script searches for the binary in user-defined environment variables, the system PATH, standard macOS application bundles, and relative build directories.
  • While execution is limited to specific command-line arguments (index status, search, session read), the discovery process involves multiple file system checks.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves content from past conversation transcripts which acts as untrusted input when processed by the agent in a new session.
  • Ingestion points: Untrusted data enters the agent context through the stdout of the ataru binary, which is parsed and projected by scripts/ataru_recall.py.
  • Boundary markers (absent): While SKILL.md instructs the agent to use citations and avoid speculation, no technical delimiters (such as XML tags or specific markdown blocks) are mandated to isolate the historical snippets from the primary prompt.
  • Capability inventory: The skill possesses the capability to read local transcript files (via the binary) and perform atomic writes to a local profile JSON file (profile_store.py).
  • Sanitization: The skill implements basic sanitization by projecting only relevant fields from the raw JSON output and clipping message bodies to a maximum of 2000 characters by default.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 08:32 AM
Security Audit — agent-trust-hub — lov-search-chat