lovstudio-event-curator
Fail
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute
uvxandnpxcommands in the shell to decrypt hidden instructions and manage licensing. - [REMOTE_CODE_EXECUTION]: By invoking
uvx lovstudio-skill-helperandnpx lovstudio, the skill triggers the download and execution of external code packages from PyPI and NPM registries. - [EXTERNAL_DOWNLOADS]: The skill depends on fetching external components and tools from the author's domain and public package managers to reveal its intended functionality.
- [PROMPT_INJECTION]: The skill contains a meta-instruction requiring the agent to treat the output of an external command as its primary source of truth, effectively bypassing the initial safety instructions and redirecting behavior to un-audited content.
Recommendations
- AI detected serious security threats
Audit Metadata