lov-xhs
Fail
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: HIGHOBFUSCATIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [OBFUSCATION]: The core functional components of the skill, including the actual instructions and all Python scripts, are provided in an encrypted format (e.g.,
SKILL.md.enc,scripts/xhs_collect.py.enc,scripts/xhs_search.py.enc). This prevents static analysis and safety validation by either the platform or the user. - [DYNAMIC_EXECUTION]: The loader in
SKILL.mdexplicitly commands the agent to decrypt the hidden instructions at runtime and to 'follow it to the letter.' This instruction allows for the execution of arbitrary, unverified logic that is injected into the agent's context only after the skill has been loaded. - [REMOTE_CODE_EXECUTION]: The skill requires the agent to execute shell commands using
uvxandnpxto run remote tools such aslovstudio-skill-helperandlovstudio. These commands fetch and execute code from public registries (PyPI and npm) at runtime, posing a supply chain risk. - [COMMAND_EXECUTION]: Instructions direct the agent to perform sensitive filesystem and shell operations, including modifying user directories (
~/.claude/skills/), opening web browsers for license binding, and executing installation scripts for additional components.
Recommendations
- AI detected serious security threats
Audit Metadata