lighthouse

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill specification is coherently aligned with its stated purpose of automated Lighthouse score improvement using PSI API, with appropriate workflow phases and guardrails. The main security considerations are the handling of the PSI API key via environment variables, external API calls, and reporting. No evidence of malicious activity or data exfiltration beyond legitimate API usage. Recommend ensuring secret handling practices (avoid logging API keys, secure CI/CD secret management) and verifying that the psi-measure.mjs script enforces rate limits and secure API usage.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 04:33 AM
Package URL
pkg:socket/skills-sh/tezuka-Akihiro%2FClaudeMix%2Flighthouse%2F@e2ab272732590b29f54868f6e3297053b178f6db