staticflow-kiro-log-diagnoser

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and local log-analysis capabilities are internally coherent, and no direct exfiltration or credential harvesting is described. However, it relies on an unverifiable sf-cli with unclear publisher provenance and undisclosed data flow, which is disproportionate trust for a diagnostic skill and pushes overall risk into the high range.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:42 AM
Package URL
pkg:socket/skills-sh/acking-you%2Fcodex-bridge%2Fstaticflow-kiro-log-diagnoser%2F@6bd1f9daf1cddc6cbc793032327d429dd4ea2204