flows-app-review

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and official GitHub source are broadly aligned, but its core logic is fetched dynamically from a remote repository and then executed/followed with Shell and Write access. This creates a meaningful supply-chain and indirect prompt-injection risk despite no clear evidence of credential theft or overtly malicious behavior.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 7, 2026, 06:07 PM
Package URL
pkg:socket/skills-sh/cognitedata%2Fbuilder-skills%2Fflows-app-review%2F@18e2af4b8535d6ec86252350ba0d9eb4337ce9ef