lazyweb-design-brainstorm

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core research/report behavior fits the stated design-brainstorm purpose, but the skill expands trust by invoking other local skill binaries and instructing installation of a separate Lazyweb plugin via a one-line prompt. It also mixes untrusted web content with Bash and file-writing capabilities, creating moderate prompt-injection and supply-chain risk despite no clear credential theft or overt exfiltration.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 09:56 PM
Package URL
pkg:socket/skills-sh/aboul3ata%2Flazyweb-skill%2Flazyweb-design-brainstorm%2F@9b7f9e5b24b6a970d9765436d4958f82a212b0a0