codeflow

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose mostly matches codebase visualization, but trust is weakened by recommending a mutable third-party hosted frontend for private-repo tokens and by instructing transitive skill installation via npx. Self-hosting from the linked upstream repo is more coherent; the online/private-token path is the main risk.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
Jul 28, 2026, 01:54 PM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Fcodeflow%2F@80aa917ce65b3631db71c78d8e0da347ddd1eccc4f10af046fef4e9516cf1fcd
Security Audit — socket — codeflow