flows-agent
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's broad paid-API gateway model is coherent with its stated purpose, and the endpoint is on the publisher's own domain, so this is not confirmed malware. However, it centralizes many unrelated capabilities, routes user data through an intermediary to multiple third-party providers, and includes autonomous outbound messaging actions, making the scope and data flows higher risk than a narrowly scoped API integration.
Confidence: 85%Severity: 58%
Audit Metadata