flow-next-opencode-work

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow is broadly aligned with a local task-execution skill, but its trust model depends on an unverified bundled executable (flowctl) and partially hidden linked phases. No clear credential harvesting or exfiltration is shown, yet the unverifiable binary and broad repo-modifying powers raise the overall security risk above benign.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Apr 7, 2026, 09:08 AM
Package URL
pkg:socket/skills-sh/gmickel%2Fflow-next-opencode%2Fflow-next-opencode-work%2F@6b1f146df57ca1219e448cbdf63cd30e565505bf