luzia

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Anomaly
AnomalyLOW
package.json

The package will execute bundled Node scripts during install and uninstall. This is a legitimate pattern for setting up runtime assets, but it carries moderate risk because those scripts run with the installer's privileges and could perform malicious actions (data exfiltration, modifying files, creating hooks, running remote code). Inspect install-skill.js and uninstall-skill.js before installing or run installation in a sandboxed environment.

Confidence: 80%Severity: 60%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:34 PM
Package URL
pkg:socket/skills-sh/luziadev%2Fskill%2Fluzia%2F@12f397293ca754bb96865f928535f781a58a88a8