lov-organize-storage

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/storage_organizer.py

The code is a legitimate storage inventory and file-move utility with no apparent malware or exfiltration behavior. It has two important security weaknesses: apply_plan() can be abused through a tampered plan to operate outside the intended root, and write_rollback() can generate shell-injection commands from specially crafted paths. The apparent unmatched parenthesis at the end would also prevent execution as supplied.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 10, 2026, 02:49 AM
Package URL
pkg:socket/skills-sh/lovstudio%2Fskills%2Flov-organize-storage%2F@c2055302ef6243a6cd5e07ee875913db45efe01825049bd96ff0cc1b61c1be8f
Security Audit — socket — lov-organize-storage