lov-typeless-prompt
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is benign, but the delivered footprint is a closed, encrypted loader whose real instructions are hidden until runtime. Same-org npm/PyPI distribution makes this less likely to be outright malware, yet the unauditable decrypted content and optional hidden files create a disproportionate trust gap for a simple writing-assistance skill.
Confidence: 86%Severity: 74%
Audit Metadata