ljg-word-flow

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a word-analysis/card-generation skill, and no credential theft or external exfiltration is evident. However, the core functionality relies on two undocumented, publicly unverifiable CLIs (`ljg-word`, `ljg-card`), making this a high supply-chain risk skill even without overtly malicious behavior.

Confidence: 83%Severity: 82%
Audit Metadata
Analyzed At
Mar 27, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/yelban%2Fljg-skills.TW%2Fljg-word-flow%2F@89604f0495a40a9535bc21d4c8f973ea5454e37e