fizzy-workflow

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the workflow is mostly aligned with its stated Fizzy card-management purpose, but it expands trust in two notable ways: it requires an external standalone CLI binary and instructs installation of a second skill, creating a transitive trust chain. Data flows are otherwise proportionate and there is no clear credential harvesting or malicious exfiltration behavior in the provided instructions.

Confidence: 80%Severity: 62%
Audit Metadata
Analyzed At
Mar 13, 2026, 06:26 AM
Package URL
pkg:socket/skills-sh/akhy%2Fagent-skills%2Ffizzy-workflow%2F@a3904d779741a36fc84ac6ca4c2199ad2bcbdb5f