lovstudio-proposal

Warn

Audited by Socket on Jul 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is benign, but the skill's real instructions are encrypted, remotely decrypted on each run, and mediated by third-party CLI tooling with inconsistent publisher provenance. That hidden control plane is not proportionate to a proposal-generation skill and prevents verification of what data or permissions the decrypted payload will use.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Jul 29, 2026, 02:56 PM
Package URL
pkg:socket/skills-sh/lovstudio%2Fgeneral-skills%2Flovstudio-proposal%2F@08b638f56f63819196ea3964e19e626f96ff530d10944bf07f1dfc2397e6f498
Security Audit — socket — lovstudio-proposal