lov-sync-with-synology

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The CLI script scripts/synology_cli.py uses subprocess.run to interact with the macOS security command. This is a secure and legitimate implementation designed to retrieve DSM passwords from the system Keychain rather than storing them in plain text.
  • [EXTERNAL_DOWNLOADS]: The scripts/install.sh script installs standard Python dependencies from PyPI, such as requests, synology-api, and tqdm. These libraries are required for the tool's network operations and user interface.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes local file metadata (filenames) and reports them in its output, which presents a theoretical surface for indirect prompt injection.
  • Ingestion points: Local file paths are ingested by scripts/synology_cli.py during the filesystem scanning phase.
  • Boundary markers: The tool uses structured JSON for its final summary and audit logs, providing data separation.
  • Capability inventory: Capabilities include network requests (for file upload), file system modifications (move to trash/delete), and shell execution (for Keychain access).
  • Sanitization: Relies on standard library JSON serialization to handle potentially unusual filename characters in the output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 02:15 AM
Security Audit — agent-trust-hub — lov-sync-with-synology