kestra-flow
Fail
Audited by Socket on Mar 11, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The Kestra Flow Skill as described is largely consistent with its stated purpose: it fetches a live schema, uses defined rules to generate or modify Kestra Flow YAML, and outputs the result. Data flows are limited to user inputs and a single public API schema fetch, with proper handling of secrets and no evident credential theft or exfiltration. The reliance on curl for a live schema endpoint is typical for schema-driven tooling and does not appear to introduce harmful data paths. Overall, the footprint is benign and proportionate to the stated goal, with minor caveats around external network dependency that are expected in this context.
Confidence: 98%
Audit Metadata