skills/lovstudio/skills/lov-xhs/Gen Agent Trust Hub

lov-xhs

Fail

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: HIGHOBFUSCATIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [OBFUSCATION]: The core functional components of the skill, including the actual instructions and all Python scripts, are provided in an encrypted format (e.g., SKILL.md.enc, scripts/xhs_collect.py.enc, scripts/xhs_search.py.enc). This prevents static analysis and safety validation by either the platform or the user.
  • [DYNAMIC_EXECUTION]: The loader in SKILL.md explicitly commands the agent to decrypt the hidden instructions at runtime and to 'follow it to the letter.' This instruction allows for the execution of arbitrary, unverified logic that is injected into the agent's context only after the skill has been loaded.
  • [REMOTE_CODE_EXECUTION]: The skill requires the agent to execute shell commands using uvx and npx to run remote tools such as lovstudio-skill-helper and lovstudio. These commands fetch and execute code from public registries (PyPI and npm) at runtime, posing a supply chain risk.
  • [COMMAND_EXECUTION]: Instructions direct the agent to perform sensitive filesystem and shell operations, including modifying user directories (~/.claude/skills/), opening web browsers for license binding, and executing installation scripts for additional components.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 10, 2026, 02:01 AM
Security Audit — agent-trust-hub — lov-xhs