lov-any2pdf

Warn

Audited by Socket on Sep 30, 2026

1 alert found:

Security
SecurityMEDIUM
.github/workflows/release.yml

The workflow has a significant command-injection risk because a manually supplied tag is interpolated into shell scripts. The fixed GITHUB_OUTPUT delimiter also allows crafted changelog content to alter step outputs. These are workflow security weaknesses with potential impact through the release-writing permission; the fragment does not itself establish malicious intent.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 30, 2026, 03:44 AM
Package URL
pkg:socket/skills-sh/lovstudio%2Fany2pdf-skill%2Flov-any2pdf%2F@914578ef02f7628a380245d6575353e2914a965c
Security Audit — socket — lov-any2pdf