lazyweb-design-improve

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains logic to locate and execute a local browser binary (named 'browse') for navigating websites, taking snapshots of web content, and capturing screenshots for design analysis.
  • [EXTERNAL_DOWNLOADS]: Performs downloads of image files from remote URLs provided by the Lazyweb MCP service and external web searches using the 'curl' utility.
  • [PROMPT_INJECTION]: Ingests external data through visual descriptions from the Lazyweb database and text snapshots of third-party websites, representing a surface for indirect prompt injection where adversarial content could influence the generated improvement report.
  • [DATA_EXFILTRATION]: Accesses the local configuration file '~/.lazyweb/libraries.json' to identify and search user-connected inspiration sources like Mobbin or Savee.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 09:55 PM
Security Audit — agent-trust-hub — lazyweb-design-improve