lov-media-publisher
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local system utilities for non-malicious tasks. Evidence:
scripts/check_video.pycallsffprobeto validate video technical specifications. Evidence:scripts/notify_user.pyusesosascriptandsayon macOS to provide user notifications and audio feedback. - [INDIRECT_PROMPT_INJECTION]: The skill automates interactions with external web platforms, creating a potential surface for indirect prompt injection from platform-controlled data. Ingestion points: Browser DOM snapshots and video metadata. Boundary markers: The skill instructions require the agent to generate and display a field verification table. Capability inventory: Browser automation (form filling and submission) and local command execution. Sanitization: A mandatory
awaiting_confirmationhuman review step is implemented to verify the final publication state, effectively mitigating risks of automated obedience to malicious external instructions.
Audit Metadata