lov-organize-storage

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard system utilities du and lsof via Python's subprocess module to gather directory sizes and detect open file handles. These operations are limited to read-only diagnostic tasks intended to support the skill's safety logic (e.g., checking for recent activity or open writers before a move).
  • [PERSISTENCE]: The scripts/profile_store.py utility manages a local JSON profile to store user preferences and workspace facts across sessions. The script includes security controls that explicitly prevent the persistence of sensitive fields such as tokens, secrets, and passwords.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of directory and file names when performing an inventory of the target storage volume.
  • Ingestion points: File and directory names read via os.scandir in scripts/storage_organizer.py.
  • Boundary markers: None identified for file name processing.
  • Capability inventory: File renaming (os.rename), and shell utility execution (du, lsof) in scripts/storage_organizer.py.
  • Sanitization: Path inputs are normalized via posixpath.normpath and checked for root escape patterns, though names themselves are not sanitized for LLM-targeting instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 02:48 AM
Security Audit — agent-trust-hub — lov-organize-storage