flowstudio-power-automate-build
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is coherent with its stated purpose, but it routes powerful Power Automate management and testing through a third-party hosted MCP service using a vendor-issued token rather than official Microsoft APIs. No malware-like installer or hidden exfiltration is present, yet the credential forwarding and ability to trigger side-effecting workflows make this medium risk.
Confidence: 89%Severity: 56%
Audit Metadata