lavish

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main behavior is coherent with visual artifact review, and the `lavish-axi` install path appears same-publisher and npm-hosted rather than an unknown binary. Risk comes from unpinned `npx` execution, transitive skill-install trust, and especially the optional `share` flow that sends artifact data and optional tokens to a third-party hosting service outside the core local review purpose.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Aug 20, 2026, 10:12 PM
Package URL
pkg:socket/skills-sh/kunchenguid%2Flavish-axi%2Flavish%2F@6704221b30ce098dd786ad929f00ec65a81dcd6dc77293d189f5aa51156a088a
Security Audit — socket — lavish