skills/lovstudio/skills/lov-five/Gen Agent Trust Hub

lov-five

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's README recommends installation via npx, and the source validation utility scripts/validate_skill.py depends on the PyYAML library, which is typically fetched from a package registry.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data and user inputs to trigger its functional modes. It defines execution boundaries in SKILL.md and incorporates manual confirmation flags in its persistence scripts to maintain user control and prevent unintended modifications.\n- [DATA_EXFILTRATION]: The skill manages local persistent state using a profile.json file in the user's config directory. It includes a security filter that specifically prevents the storage of sensitive fields such as 'token', 'secret', or 'api_key'.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 09:50 AM
Security Audit — agent-trust-hub — lov-five