lazyweb-design-research

Warn

Audited by Socket on May 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core research/reporting behavior is aligned with the stated purpose, but the skill expands trust to unverified Lazyweb installer/binary paths and combines untrusted web research with Bash+Write automation. Main risk is supply-chain/install trust plus indirect prompt injection from arbitrary web content, not confirmed malware or credential theft.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
May 2, 2026, 09:56 PM
Package URL
pkg:socket/skills-sh/aboul3ata%2Flazyweb-skill%2Flazyweb-design-research%2F@cc277bf3c2525791e6c8bf65002a817443dd50c4