flow

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose mostly matches the capabilities, and there is no explicit credential harvesting or malicious data exfiltration in the provided text. However, it is a community-published orchestrator that searches and composes third-party skills from a registry, creating transitive-trust and prompt-injection risk without clear provenance, policy boundaries, or implementation details for how retrieved skills are vetted before reuse.

Confidence: 82%Severity: 57%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:27 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fflow%2F@75d6076b146e31948ba0aafd7b181eae163fe75c