flow-walk
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. Core browser automation and Playwright usage are coherent with the skill’s purpose, and the main dependency is from an official source. Risk comes from env-var-driven flows that may capture secrets in evidence, autonomous interaction with live sites, and especially the unverifiable local evidence-upload scripts that can transmit artifacts and possibly repo auth off-box; these unknown data flows keep the skill above benign.
Confidence: 84%Severity: 61%
Audit Metadata