flow-next-opencode-interview
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and local file/task-writing behavior are coherent, and no credential harvesting or external exfiltration is shown. However, it depends on executing a bundled local `flowctl` binary with unverified provenance, which alone makes the security risk high under the mandatory override.
Confidence: 87%Severity: 70%
Audit Metadata