lazyweb-quick-references

Warn

Audited by Socket on May 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core purpose is coherent, but the skill’s execution trust is weak. It relies on unverifiable local browse binaries and transitive plugin/skill setup, while browsing untrusted web content with Bash/Write capability. I do not see clear credential theft or exfiltration, so this is high-risk/vulnerable rather than confirmed malware.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
May 2, 2026, 09:56 PM
Package URL
pkg:socket/skills-sh/aboul3ata%2Flazyweb-skill%2Flazyweb-quick-references%2F@a6cbf57c8450e5e89a5b3123ced879ea50da2e5c