lov-sync-with-synology
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The CLI script
scripts/synology_cli.pyusessubprocess.runto interact with the macOSsecuritycommand. This is a secure and legitimate implementation designed to retrieve DSM passwords from the system Keychain rather than storing them in plain text. - [EXTERNAL_DOWNLOADS]: The
scripts/install.shscript installs standard Python dependencies from PyPI, such asrequests,synology-api, andtqdm. These libraries are required for the tool's network operations and user interface. - [INDIRECT_PROMPT_INJECTION]: The skill processes local file metadata (filenames) and reports them in its output, which presents a theoretical surface for indirect prompt injection.
- Ingestion points: Local file paths are ingested by
scripts/synology_cli.pyduring the filesystem scanning phase. - Boundary markers: The tool uses structured JSON for its final summary and audit logs, providing data separation.
- Capability inventory: Capabilities include network requests (for file upload), file system modifications (move to trash/delete), and shell execution (for Keychain access).
- Sanitization: Relies on standard library JSON serialization to handle potentially unusual filename characters in the output.
Audit Metadata