lov-cli2anything

Warn

Audited by Socket on Aug 27, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose and capabilities mostly align, and the instructions include sensible limits on authorization and secret handling. However, the core bundled cli2anything++ runtime is not externally verifiable from the provided evidence, so install/execution trust is disproportionately weak for a skill that can ingest sensitive session-derived API evidence and generate runnable artifacts.

Confidence: 84%Severity: 78%
AnomalyLOW
src/extension-bridge.mjs

No clear malicious payload or malware behavior is present. The code implements an extension-backed local HTTP proxy. The principal risks are an unauthenticated loopback API, wildcard CORS, unrestricted proxy URLs and request data, forged result submission if identifiers are obtained, and unbounded request-body buffering. URL allowlisting, authentication or per-session tokens, strict Origin validation, result schema validation, and body-size limits are recommended.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Aug 27, 2026, 06:59 AM
Package URL
pkg:socket/skills-sh/lovstudio%2Fskills%2Flov-cli2anything%2F@4b47180ef62f654cb7f39e1d0c247e56e2f3b5a8b399e2586236e60f02b7cb75
Security Audit — socket — lov-cli2anything