lov-skill-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/inspect_layout.py uses subprocess.run to execute Git commands (rev-parse, status, branch) to gather repository information. These calls are implemented using list-based arguments to avoid shell injection vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external files (SKILL.md, README.md, scripts) from other skills to perform audits and optimizations.
  • Ingestion points: scripts/lint_skill.py and scripts/bump_version.py read content from target skill directories.
  • Boundary markers: No explicit delimiters are used to wrap ingested content in the agent prompt, relying instead on the structured workflow steps.
  • Capability inventory: The skill can write to the filesystem (path.write_text, shutil.copy2) and execute Git commands (subprocess.run).
  • Sanitization: The tool uses regular expressions for analysis and modification rather than rigorous sanitization of input data.
  • [DATA_EXFILTRATION]: The workflow includes git push origin HEAD to synchronize changes with a remote repository. This is an intended functional behavior for a version management tool and uses the user's existing Git configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:08 PM
Security Audit — agent-trust-hub — lov-skill-optimizer