staticflow-kiro-log-diagnoser
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose and local log-analysis capabilities are internally coherent, and no direct exfiltration or credential harvesting is described. However, it relies on an unverifiable sf-cli with unclear publisher provenance and undisclosed data flow, which is disproportionate trust for a diagnostic skill and pushes overall risk into the high range.
Confidence: 82%Severity: 72%
Audit Metadata