lazyweb-design-research
Warn
Audited by Socket on May 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core research/reporting behavior is aligned with the stated purpose, but the skill expands trust to unverified Lazyweb installer/binary paths and combines untrusted web research with Bash+Write automation. Main risk is supply-chain/install trust plus indirect prompt injection from arbitrary web content, not confirmed malware or credential theft.
Confidence: 84%Severity: 78%
Audit Metadata