lov-wechat-article-branding-skill
Audited by Socket on Aug 11, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The stated purpose is plausible, and the npm install path appears Lovstudio-branded, but the skill’s real behavior is concealed behind encrypted distribution and a separate decryption helper. Because the operative skill content is unverifiable and may handle login-protected decryption plus article data, the install and data-flow trust are not proportionate to a simple branding skill.
The provided fragment is not valid/readable source code, so source-to-sink flows and malicious behaviors (networking, execution, exfiltration, sabotage, credential theft) cannot be confirmed within this module. The main finding is a reviewability anomaly: the content appears to be a compiled binary, packed payload, or corrupted dump. Provide the original file contents in text form (or a decoded/decompressed/decompiled representation) to enable a meaningful security assessment.