lov-skill-publisher
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill follows security best practices for developer automation tools. It avoids hardcoding sensitive credentials, instead relying on environment variables (e.g.,
LOVSTUDIO_REVALIDATE_SECRET) and established CLI authentication (gh auth). The provided Python scripts utilizeyaml.safe_load()to mitigate risks associated with parsing untrusted YAML data, and the documentation explicitly instructs the user to keep platform metadata and secrets outside of the canonical source code. - [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands to automate the release process.
- Evidence: The workflow utilizes
git,gh,python3, andcurlto initialize repositories, tag releases, build packages, and trigger site revalidation. These commands are legitimate for the skill's stated purpose of being a publisher and are performed using established, well-known software tools. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from other local skill files, which creates an attack surface for indirect prompt injection, although it is mitigated through validation.
- Ingestion points: The publishing process involves reading
SKILL.mdandkit.yamlfrom local directories to extract metadata like names, descriptions, and versions. - Boundary markers: The skill workflow includes a mandatory validation step (
scripts/validate_skill.py) that must pass before any publishing actions are taken. - Capability inventory: The skill possesses the ability to execute shell commands, perform network requests to specific endpoints, and write to the local file system (e.g., creating ZIP archives).
- Sanitization: The
scripts/validate_skill.pyscript enforces strict naming (kebab-case) and versioning (SemVer) rules via regex, and utilizesyaml.safe_loadto prevent code execution during file ingestion.
Audit Metadata