lov-write-professional-book

Warn

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: MEDIUMOBFUSCATIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [OBFUSCATION]: The core logic and instructions of the skill are stored in encrypted binary files (SKILL.md.enc and references/workflow.md.enc). The encryption is managed via AES-256-GCM as documented in MANIFEST.enc.json, which prevents verification of the content during static analysis.
  • [REMOTE_CODE_EXECUTION]: The installation and usage process relies on external package runners to fetch and execute tools. Specifically, it uses npx lovstudio and uvx lovstudio-skill-helper to download and process the skill content. This involves running code from external registries (NPM and PyPI) that is not included in the skill package itself.
  • [DYNAMIC_EXECUTION]: The skill content is decrypted and loaded into the agent's context dynamically at runtime. This mechanism allows for the execution of instructions that are not visible or verifiable until the decryption step occurs, bypassing standard static safety checks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 7, 2026, 09:51 PM
Security Audit — agent-trust-hub — lov-write-professional-book