flowchad-setup
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core repo discovery and Flowchad scaffolding are mostly aligned with the stated purpose, but the skill silently reads sensitive local config areas, solicits test credentials, and configures unpinned third-party MCP tooling that may later receive analytics secrets. No clear malicious exfiltration is present, but the trust and scope are broader than a minimal setup helper.
Confidence: 82%Severity: 56%
Audit Metadata