lovstudio-event-curator

Fail

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute uvx and npx commands in the shell to decrypt hidden instructions and manage licensing.
  • [REMOTE_CODE_EXECUTION]: By invoking uvx lovstudio-skill-helper and npx lovstudio, the skill triggers the download and execution of external code packages from PyPI and NPM registries.
  • [EXTERNAL_DOWNLOADS]: The skill depends on fetching external components and tools from the author's domain and public package managers to reveal its intended functionality.
  • [PROMPT_INJECTION]: The skill contains a meta-instruction requiring the agent to treat the output of an external command as its primary source of truth, effectively bypassing the initial safety instructions and redirecting behavior to un-audited content.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 29, 2026, 02:54 PM
Security Audit — agent-trust-hub — lovstudio-event-curator