lavish
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s main behavior is coherent with visual artifact review, and the `lavish-axi` install path appears same-publisher and npm-hosted rather than an unknown binary. Risk comes from unpinned `npx` execution, transitive skill-install trust, and especially the optional `share` flow that sends artifact data and optional tokens to a third-party hosting service outside the core local review purpose.
Confidence: 87%Severity: 58%
Audit Metadata