lov-feedback-loop
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated feedback-loop purpose is plausible, and the helper appears to be a real Lovstudio-associated PyPI package, but the skill’s true instructions are encrypted, dynamically decrypted, and then executed/obeyed without review. That hidden-behavior model, plus transitive skill installation and external helper control, makes the footprint insufficiently transparent for its claimed purpose.
Confidence: 85%Severity: 76%
Audit Metadata