flowstudio-power-automate-governance

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely coherent with its stated Power Automate governance purpose and does not contain malware-like install or exfiltration behavior. The main risk is data-flow trust: a third-party hosted MCP service receives the API token and tenant metadata, and the skill can make operational changes like stopping flows and changing notification settings. This looks like a legitimate hosted governance integration, but it carries medium risk due to intermediary credential/data routing and real-world action capability.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 9, 2026, 01:04 AM
Package URL
pkg:socket/skills-sh/github%2Fawesome-copilot%2Fflowstudio-power-automate-governance%2F@333cf82e7611dc2862c1d50ca7efb2627d5c51a3