flowstudio-power-automate-debug

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose of diagnosing Power Automate flows via FlowStudio MCP. It primarily performs authenticated API calls to a central MCP service and surfaces diagnostic data back to the user. Key security considerations include the centralization of sensitive JWT tokens to MCP, reliance on external network calls, and the need for clear data retention and access controls. No download/install of unverifiable binaries is involved, and no direct credential exfiltration beyond MCP interactions is evident in the provided material. Overall, the skill is SUSPICIOUS to MEDIUM risk due to credential exposure surface and reliance on an external diagnostic service, but not malicious given the described usage and absence of external data exfiltration beyond MCP communications.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 11:23 PM
Package URL
pkg:socket/skills-sh/github%2Fawesome-copilot%2Fflowstudio-power-automate-debug%2F@78945675ad018875ddeff77455c2a163986ef848