flow-next-opencode-impl-review

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s review purpose is coherent, but its actual footprint depends on a bundled repo-local flowctl executable and an externally trusted rp-cli/backend path that are not well verified here. Code is also sent to outside review systems, and the skill supports an autonomous fix/commit/re-review loop. Main concern is install/execution trust rather than confirmed malicious intent.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Apr 7, 2026, 09:09 AM
Package URL
pkg:socket/skills-sh/gmickel%2Fflow-next-opencode%2Fflow-next-opencode-impl-review%2F@b00eb4651030131f0a2688b28c43089b90544d68