lov-wechat-article-branding-skill
Fail
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill payload, including all prompts and Python scripts (validate_skill.py, validate_brand_profile.py), is encrypted using AES-256-GCM. The skill uses a helper tool (lovstudio-skill-helper) to decrypt and execute this logic at runtime, effectively hiding its actual behavior from audit.
- [EXTERNAL_DOWNLOADS]: The skill setup requires downloading external tools and encrypted distribution packages from the author's infrastructure using npx and uvx.
- [COMMAND_EXECUTION]: The SKILL.md documentation instructs the user or agent to execute shell commands to add and decrypt the skill, which involves running unverified binary code from the network.
- [PROMPT_INJECTION]: The skill processes external WeChat articles. Because the internal instructions are encrypted, it is impossible to verify if proper sanitization, boundary markers, or security guardrails are implemented to protect against indirect prompt injection.
Recommendations
- AI detected serious security threats
Audit Metadata