flutter-health-audit

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's overall goal is coherent, but it goes beyond passive auditing by installing tools, resolving dependencies, and executing build/test code from the target repository. The hidden reference instructions prevent verification of installer provenance, and the optional invocation of a second skill adds transitive trust risk. No clear credential theft or exfiltration is shown, so this is not confirmed malware.

Confidence: 82%Severity: 63%
Audit Metadata
Analyzed At
Mar 25, 2026, 05:40 PM
Package URL
pkg:socket/skills-sh/somnio-software%2Ftechnology-tools%2Fflutter-health-audit%2F@59ef2e2275a999ef959eb1d01ea89e77d1639df3