flow-next-opencode-interview

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and local file/task-writing behavior are coherent, and no credential harvesting or external exfiltration is shown. However, it depends on executing a bundled local `flowctl` binary with unverified provenance, which alone makes the security risk high under the mandatory override.

Confidence: 87%Severity: 70%
Audit Metadata
Analyzed At
Apr 7, 2026, 09:08 AM
Package URL
pkg:socket/skills-sh/gmickel%2Fflow-next-opencode%2Fflow-next-opencode-interview%2F@0e02a81b676899507929da7319e196aa05b42e54