lov-skill-creator

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's test suite (scripts/test_profile_contract.py) employs subprocess.run to verify the functionality of internal scripts during development and installation, which is a standard and safe testing practice.
  • [INDIRECT_PROMPT_INJECTION]: The migration utility (scripts/migrate_command.py) processes legacy markdown instructions. Although this involves ingesting untrusted data, the skill mitigates injection risks by using deterministic regex analysis to flag issues and strict formatting templates for generating new skill files, avoiding unsafe execution of external content.
  • [SAFE]: No malicious patterns were identified. The skill adheres to security best practices, such as implementing a blocklist for sensitive keys (e.g., tokens, passwords) in its profile storage system and utilizing atomic write operations with restricted file permissions (0o600) to ensure data integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:08 PM
Security Audit — agent-trust-hub — lov-skill-creator