lovable

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md is principally documentation and prompt guidance for Lovable.dev + Supabase projects. I find no direct malicious code or obfuscation in the file. The primary risk is operational: enabling 'yolo' browser automation allows an agent/extension to perform high-privilege operations (deployments, apply migrations) on behalf of the user — if the automation component or the agent is compromised, that capability could be abused. Recommend auditing the /skills/yolo implementation and any Chrome extension, enforcing least privilege, requiring explicit operator confirmation before destructive actions, and clarifying how sessions/credentials are protected. Otherwise, the skill itself is coherent with its purpose and not malicious.

Confidence: 80%Severity: 20%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:07 PM
Package URL
pkg:socket/skills-sh/10k-digital%2Flovable-claude-code%2Flovable%2F@1ca9a8b8a7bccf47d10373ceec014a0a53bbfd7c