lov-publish-event-onto-hdx

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS due to install/execution trust, not overt malicious behavior. The skill's capabilities fit its stated Huodongxing diagnostic purpose and its data flow stays mostly first-party, but it depends on an externally distributed browser app/binary (`ego-browser`) that inherits the user's authenticated session and is not fully verifiable from source or checksum/signature evidence. That makes the overall security risk high despite otherwise coherent scope.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Sep 7, 2026, 09:40 PM
Package URL
pkg:socket/skills-sh/lovstudio%2Fskills%2Flov-publish-event-onto-hdx%2F@e43157e2005b0e4c5218812f4378fbec966d936b14656d61c028fb3dd920d958
Security Audit — socket — lov-publish-event-onto-hdx