yolo

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The combined analyses describe a coherent, purpose-aligned browser-automation deployment skill with explicit fallbacks and testing. There is no clear malware or credential-harvesting behavior detected. The auto-deploy-after-push capability introduces deployment risk if misconfigured or if UI changes occur, and the reliance on a specific browser-extension increases maintenance and supply-chain risk. The evidence supports a mostly benign posture provided proper access controls, secure secret handling, and robust monitoring are enforced.

Confidence: 59%Severity: 60%
Audit Metadata
Analyzed At
Feb 16, 2026, 02:41 AM
Package URL
pkg:socket/skills-sh/10k-digital%2Flovable-claude-code%2Fyolo%2F@61a45963f4d874a3662caeb72e7383c881d680d9