lov-skill-add-case

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/add_case_with_session.py invokes the lov-share-session utility using subprocess.run. This execution is used to upload redacted session transcripts as part of the case submission workflow. The command is constructed as a list using the current Python executable (sys.executable) and incorporates arguments validated by argparse, which mitigates risks associated with shell command injection.- [DYNAMIC_EXECUTION]: The script scripts/add_case_with_session.py dynamically loads the local add_case.py module at runtime using importlib.util.module_from_spec. This pattern is used to share core validation logic between different entry points in the skill package. Since the loading is restricted to local scripts within the skill's own directory, it is considered a safe implementation of modular code execution.- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from previous agent tasks to generate cases, which represents a potential indirect prompt injection surface. The skill implements a strong defense-in-depth approach by requiring explicit user confirmation of the final artifact, providing a full preview of the submission bundle, and using regular expression scanners to automatically detect and block the inclusion of API keys, tokens, or private system paths in the public output.- [DATA_EXFILTRATION]: Network activity is primarily directed toward the lovstudio.ai domain for authentication and data submission. The skill includes a dedicated verification step in scripts/submit_case.py that uses the ipaddress module to ensure provided URLs are global and do not target local or internal network interfaces, effectively preventing Server-Side Request Forgery (SSRF) attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:08 PM
Security Audit — agent-trust-hub — lov-skill-add-case