lovstudio-business-card

Warn

Audited by Socket on Jul 29, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/modern-screenshot.umd.js

No definitive malware indicators (no credential theft, backdoor, persistence, or direct eval/exec of attacker-controlled code) are visible in this module. The security risk is primarily due to capability breadth: it can fetch and inline remote resources referenced by attacker-influenced DOM/CSS and can load caller-supplied Web Workers (workerUrl execution boundary). If the consuming application processes untrusted DOM/CSS or untrusted options, the module may cause unintended outbound requests and increase rendering/injection attack surface in the generated SVG/stylesheet context.

Confidence: 62%Severity: 50%
Audit Metadata
Analyzed At
Jul 29, 2026, 02:55 PM
Package URL
pkg:socket/skills-sh/lovstudio%2Fgeneral-skills%2Flovstudio-business-card%2F@2313d498c8aad863bcfb326fca19144ea49c42d764032d7daf0028a3859f312d
Security Audit — socket — lovstudio-business-card