lovstudio-bp

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local Python scripts (init_bp.py and audit_bp.py) to initialize workspaces, render templates, and perform deterministic auditing of business plan outlines. These scripts are transparent and use standard Python libraries for file I/O and text processing.
  • [EXTERNAL_DOWNLOADS]: The skill kit involves the installation and execution of related Node.js packages and tools (e.g., lovstudio-any2deck) developed by the same author. These represent modular dependencies necessary for the skill's primary purpose of generating PPTX/PDF documents.
  • [PROMPT_INJECTION]: The skill processes untrusted project materials, such as documentation, websites, and founder notes, to generate business narratives. This represents an indirect prompt injection surface; however, the skill incorporates structured gates (evidence gate, visual gate) and deterministic auditing scripts to verify that generated content remains grounded in provided facts rather than external instructions.
  • [DATA_EXFILTRATION]: While the skill handles sensitive business and financial information, the scripts and instructions do not contain network exfiltration patterns. The skill explicitly warns users against storing sensitive credentials or private customer data within the business plan workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 02:20 AM
Security Audit — agent-trust-hub — lovstudio-bp