lov-search-chat
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/ataru_recall.pydiscovers and executes a local binary (typicallyataruorlovcode) using thesubprocessmodule to perform searches and read transcripts. - The script searches for the binary in user-defined environment variables, the system PATH, standard macOS application bundles, and relative build directories.
- While execution is limited to specific command-line arguments (
index status,search,session read), the discovery process involves multiple file system checks. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves content from past conversation transcripts which acts as untrusted input when processed by the agent in a new session.
- Ingestion points: Untrusted data enters the agent context through the stdout of the
atarubinary, which is parsed and projected byscripts/ataru_recall.py. - Boundary markers (absent): While
SKILL.mdinstructs the agent to use citations and avoid speculation, no technical delimiters (such as XML tags or specific markdown blocks) are mandated to isolate the historical snippets from the primary prompt. - Capability inventory: The skill possesses the capability to read local transcript files (via the binary) and perform atomic writes to a local profile JSON file (
profile_store.py). - Sanitization: The skill implements basic sanitization by projecting only relevant fields from the raw JSON output and clipping message bodies to a maximum of 2000 characters by default.
Audit Metadata