lazyweb-add-inspo-source
Warn
Audited by Socket on Mar 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s purpose and requested access are mostly coherent for connecting inspiration sites, but it relies on an unverifiable local browse binary/setup path that handles authenticated browser sessions and preserved cookies. That makes it suspicious rather than clearly malicious: the main risk is credential/session forwarding to opaque third-party code, not overt exfiltration in the visible instructions.
Confidence: 82%Severity: 82%
Audit Metadata