lov-version-management-manual

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local CLI tools and scripts to analyze git diffs and manage package versions. This is the intended purpose of the tool and is performed within the project context.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from project files (such as diff outputs) to generate changeset drafts. The risk is mitigated by a mandatory human review step where the user inspects and edits the draft in their preferred editor before final validation.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The included profile_store.py script manages user identity and workspace preferences locally. It contains explicit logic to block the persistence of sensitive data such as passwords, tokens, and API keys, reducing the risk of accidental credential exposure in configuration files.\n- [SAFE]: All scripts and dependencies are focused on local versioning workflows and maintenance of user preferences, with no evidence of unauthorized network activity or malicious behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 09:49 AM
Security Audit — agent-trust-hub — lov-version-management-manual