lov-media-publisher

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local system utilities for non-malicious tasks. Evidence: scripts/check_video.py calls ffprobe to validate video technical specifications. Evidence: scripts/notify_user.py uses osascript and say on macOS to provide user notifications and audio feedback.
  • [INDIRECT_PROMPT_INJECTION]: The skill automates interactions with external web platforms, creating a potential surface for indirect prompt injection from platform-controlled data. Ingestion points: Browser DOM snapshots and video metadata. Boundary markers: The skill instructions require the agent to generate and display a field verification table. Capability inventory: Browser automation (form filling and submission) and local command execution. Sanitization: A mandatory awaiting_confirmation human review step is implemented to verify the final publication state, effectively mitigating risks of automated obedience to malicious external instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 12:56 AM
Security Audit — agent-trust-hub — lov-media-publisher