lovstudio-finder-action

Warn

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill generates executable shell scripts and Swift source code at runtime. A specific 'Helper App' pattern is used to create an un-sandboxed application that executes content directly from the system clipboard (pbpaste) via AppleScript.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to perform complex system operations including building software with xcodebuild, registering system extensions with pluginkit, and installing binaries into the /Applications directory. It also recommends using macOS sandbox exceptions, specifically requesting read-write access to the root directory (/) via com.apple.security.temporary-exception.files.absolute-path.read-write.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 30, 2026, 02:05 PM