Back to skill

Security audit

Lovable MCP

Security checks across malware telemetry and agentic risk

Overview

This Lovable integration is useful and disclosed, but it gives an agent broad project, deployment, database, workspace, and persistent OAuth authority with weak scoping.

Install only if you intentionally want an agent to use your Lovable account for app creation, project management, database work, and deployment. Inspect the referenced setup scripts before running them, protect or avoid long-lived local token files, and require explicit approval before any delete, deploy, SQL, governance, connector, or workspace-wide action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger language is extremely broad and instructs activation for generic requests like 'make me an app' or any request involving deployment or project management. This can cause the skill to be invoked in contexts where the user did not explicitly intend to grant an external service broad access to project files, deployments, databases, analytics, or governance settings, increasing the chance of overreach and unsafe autonomous actions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises powerful capabilities such as deleting/updating projects, deploying to production, running SQL, and changing workspace governance, but it does not foreground user warnings or approval requirements near the capability description. In an agent setting, this omission increases the risk that sensitive or destructive operations occur without the user understanding the consequences or the scope of access granted.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.