lazyweb-design-improve
Warn
Audited by Socket on May 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill's purpose is coherent, but its trust model is weak. It relies on external MCP/plugin installation and third-party/local browse binaries with limited public verification, and it mixes untrusted web content with Bash and Write access. No clear credential theft or overt malicious behavior is present, but the supply-chain and indirect prompt-injection risks are significant.
Confidence: 88%Severity: 76%
Audit Metadata