lovstudio-proposal
Fail
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to execute
uvx lovstudio-skill-helper decrypt proposal. This involves running an external tool to reveal hidden instructions that are not provided in the static skill files. - [COMMAND_EXECUTION]: The agent is directed to use shell commands for license management and skill installation via
npxanduvx. - [EXTERNAL_DOWNLOADS]: The decryption and verification process requires network requests to external servers to validate licensing and fetch data.
- [PROMPT_INJECTION]: The skill directs the agent to load and "follow to the letter" instructions fetched at runtime, which is a method for dynamic instruction injection that evades safety filters and auditing.
Recommendations
- AI detected serious security threats
Audit Metadata