lov-visual-clone
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill delivers its core logic in an encrypted format (SKILL.md.enc), which is decrypted and executed at runtime using a vendor-specific helper tool. This mechanism prevents full static security auditing of the skill instructions.
- [EXTERNAL_DOWNLOADS]: The installation instructions utilize package runners to fetch vendor-owned tools and packages. Evidence includes the use of npx lovstudio and uvx lovstudio-skill-helper.
- [PROMPT_INJECTION]: The skill processes user-provided design images, which is an untrusted data ingestion point. Ingestion points: Reference design images. Boundary markers: None present in the visible skill metadata. Capability inventory: Core capabilities are hidden by encryption. Sanitization: No visible sanitization for processing external image data.
Audit Metadata