flowglad-pay-agent-card-setup

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent capability set for onboarding and managing Flowglad Pay agent cards. Key security considerations revolve around handling highly sensitive card data (number, expiry, CVC) and ensuring strict credential visibility controls (API keys, tokens) in logs and CLI output. There is no evidence of unmanaged external binaries or questionable install sources, which keeps risk moderate. The strongest concerns are potential data exposure and credential leakage in CLI/API flows; these should be mitigated with proper masking, least-privilege scopes, audit logging, and explicit data-handling policies. Overall, the footprint is proportionate to the stated purpose, but data protection specifics must be addressed to reduce risk from moderate to low.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 05:43 PM
Package URL
pkg:socket/skills-sh/flowglad%2Fpay-skills%2Fflowglad-pay-agent-card-setup%2F@3c9112cfcf01c82f7f8e195f25978909c7b4055a