flow-next-opencode-export-context
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose and capabilities mostly align, but it relies on a repo-local bundled flowctl and evals shell produced by it. Data is exported locally for manual sharing rather than covertly transmitted, so this is not confirmed malware; the main concerns are install/provenance trust and the broad sensitivity of exported repo context.
Confidence: 83%Severity: 72%
Audit Metadata