lov-oh-my-landingpage

Fail

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [OBFUSCATION]: The skill payload, including its core instructions (SKILL.md.enc), reference materials (references/*.enc), and configuration files (kit.yaml.enc), is encrypted using AES-256-GCM as defined in the MANIFEST.enc.json. This prevents any auditing of the agent's behavior, safety guidelines, or potential malicious directives.- [REMOTE_CODE_EXECUTION]: The skill documentation instructs users to execute external binaries that fetch and run remote code: 'npx lovstudio skills add oh-my-landingpage' and 'uvx lovstudio-skill-helper decrypt oh-my-landingpage'. These commands execute arbitrary logic from the lovstudio vendor's repositories on the host system.- [DYNAMIC_EXECUTION]: The skill uses a dynamic loading mechanism where instructions are decrypted directly into the agent's context at runtime. The documentation explicitly states that decrypted source code is not written to the installation directory, an evasion tactic designed to bypass file-system-based security scanners.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 24, 2026, 12:55 AM
Security Audit — agent-trust-hub — lov-oh-my-landingpage