lov-env-management

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/env_manager.py

No clear evidence of intentional malware or supply-chain sabotage in this fragment. The module is a functional secret manager/projection tool that can (by design) write secrets into local shell/system environments and perform remote validation probes that send credentials to user-supplied HTTPS endpoints. Those capabilities are the main security-relevant risks, but they appear intentional and guarded (HTTPS/local HTTP flag, redirect blocking, input validation, no eval/exec). Recommend reviewing the rest of the project (dashboard template asset, CLI entrypoints, and how registry/vault files are protected) and treat remote probe usage as high-risk if URLs/bindings can be attacker-controlled.

Confidence: 62%Severity: 50%
Audit Metadata
Analyzed At
Aug 24, 2026, 12:57 AM
Package URL
pkg:socket/skills-sh/lovstudio%2Fskills%2Flov-env-management%2F@15e6979eb3dd4fc0e0f6804aeacdac9353e79753b3e74b46226b77269b007835
Security Audit — socket — lov-env-management