flomo-analysis-studio

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose and note-access scope are coherent, but its core dependency `flomo-local-api` is not verifiably official or sourced from a trusted registry in the provided evidence. Because the skill depends on an unidentified executable that can access highly sensitive personal notes through the local desktop session, the main issue is high supply-chain/install-trust risk rather than confirmed malicious behavior.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Apr 11, 2026, 11:00 PM
Package URL
pkg:socket/skills-sh/Undertone0809%2Fflomo-skills%2Fflomo-analysis-studio%2F@259848a66143419b7703ee94667678cb84722069