lovstudio-write-professional-book

Warn

Audited by Gen Agent Trust Hub on May 3, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to decrypt instructions and manage licenses using the uvx and npx package runners.
  • [REMOTE_CODE_EXECUTION]: The agent is directed to dynamically decrypt the primary SKILL.md file and follow the resulting instructions 'to the letter.' This creates a dynamic execution path where the actual behavior of the skill is determined by external tool output at runtime.
  • [EXTERNAL_DOWNLOADS]: The skill relies on fetching remote packages (lovstudio-skill-helper and lovstudio) and performing network requests for license verification and decryption keys.
  • [REMOTE_CODE_EXECUTION]: The operational logic is stored in encrypted binary blobs (SKILL.md.enc, references/workflow.md.enc), which obfuscates the skill's intent and hides its instructions from static analysis.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 3, 2026, 04:11 AM