lazyweb-apply-design-best-practices

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose is design guidance, but its actual mechanism is to dynamically fetch and obey external skills from many third-party sources while holding write/exec-capable tools. The Lazyweb installer appears official, so this is not confirmed malware, but the transitive trust and prompt-injection surface make the skill high risk.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Aug 8, 2026, 03:06 PM
Package URL
pkg:socket/skills-sh/aboul3ata%2Flazyweb-skill%2Flazyweb-apply-design-best-practices%2F@899073b6567b7c56bea28d4c2ada35149beec864871b879d69ce4804153899fd
Security Audit — socket — lazyweb-apply-design-best-practices