lov-wdb-networkx-analysis

Fail

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: HIGHOBFUSCATIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The skill employs AES-256-GCM encryption for all functional components, including the primary instructions and all Python scripts (e.g., SKILL.md.enc, scripts/analyze.py.enc). The visible SKILL.md serves only as a bootstrap to decrypt the actual payload, hiding the skill's logic from static analysis and security auditing.
  • [DYNAMIC_EXECUTION]: The skill requires the agent to dynamically decrypt and load its instructions and referenced files (e.g., references/workflow.md) using an external tool. This mechanism allows the skill to reveal its true behavior only during execution, bypassing visibility into the logic processed by the agent.
  • [REMOTE_CODE_EXECUTION]: The skill relies on external package managers to download and execute code at runtime, specifically uvx for the Python-based lovstudio-skill-helper and npx for the Node-based lovstudio utility. These tools fetch code from public registries that are not under the platform's direct control.
  • [PROMPT_INJECTION]: The bootstrap instructions contain a directive to the agent to treat the output of an external command as its authoritative instructions ("Read it as if it were these instructions, and follow it to the letter"). This pattern is designed to hand over execution control to dynamically generated, unverified content.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 26, 2026, 10:17 AM
Security Audit — agent-trust-hub — lov-wdb-networkx-analysis