lov-write-professional-book
Warn
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: MEDIUMOBFUSCATIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [OBFUSCATION]: The core logic and instructions of the skill are stored in encrypted binary files (
SKILL.md.encandreferences/workflow.md.enc). The encryption is managed via AES-256-GCM as documented inMANIFEST.enc.json, which prevents verification of the content during static analysis. - [REMOTE_CODE_EXECUTION]: The installation and usage process relies on external package runners to fetch and execute tools. Specifically, it uses
npx lovstudioanduvx lovstudio-skill-helperto download and process the skill content. This involves running code from external registries (NPM and PyPI) that is not included in the skill package itself. - [DYNAMIC_EXECUTION]: The skill content is decrypted and loaded into the agent's context dynamically at runtime. This mechanism allows for the execution of instructions that are not visible or verifiable until the decryption step occurs, bypassing standard static safety checks.
Audit Metadata