flowdriver-covert-transport
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent, but its purpose is covert network evasion and arbitrary proxying through Google Drive. Combined with unpinned third-party source installation and forwarding of Google OAuth credentials/token files to that code and to a remote server, it presents high security risk despite not showing confirmed malware or obfuscation.
Confidence: 91%Severity: 87%
Audit Metadata