lov-media-fetch

Warn

Audited by Socket on Aug 27, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The main workflow is internally consistent for media downloading, and there is no clear credential theft or covert exfiltration. However, the skill combines autonomous network/file actions, multi-source untrusted discovery, optional third-party qBittorrent search plugins, and transitive skill loading, which makes its operational footprint riskier than a simple downloader.

Confidence: 84%Severity: 62%
AnomalyLOW
skills/media-discovery/SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its stated media-discovery purpose, but it deliberately searches torrent/DHT ecosystems and may route queries through unofficial qBittorrent plugins or other third-party indexes. No explicit credential theft, stealth, or direct malware behavior appears, yet the external search/plugin trust boundary and untrusted-content ingestion make it medium risk.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Aug 27, 2026, 07:00 AM
Package URL
pkg:socket/skills-sh/lovstudio%2Fskills%2Flov-media-fetch%2F@d352068bcc5a19e9c9448087a8d3a479ad45c9b6fa6c0f2c9ef350876eb45352
Security Audit — socket — lov-media-fetch