lovstudio-proposal

Fail

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to execute uvx lovstudio-skill-helper decrypt proposal. This involves running an external tool to reveal hidden instructions that are not provided in the static skill files.
  • [COMMAND_EXECUTION]: The agent is directed to use shell commands for license management and skill installation via npx and uvx.
  • [EXTERNAL_DOWNLOADS]: The decryption and verification process requires network requests to external servers to validate licensing and fetch data.
  • [PROMPT_INJECTION]: The skill directs the agent to load and "follow to the letter" instructions fetched at runtime, which is a method for dynamic instruction injection that evades safety filters and auditing.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 29, 2026, 02:54 PM
Security Audit — agent-trust-hub — lovstudio-proposal