flow-media

Warn

Audited by Socket on Aug 4, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the purpose is coherent, but the skill's footprint is high-trust because it installs an unofficial personal CLI and gives it access to an authenticated Google browser session to perform account-backed generation. Data appears intended for official Google Flow, not an obvious exfiltration service, so this is not confirmed malware; the main risk is credential/session exposure and supply-chain trust in third-party automation code.

Confidence: 85%Severity: 72%
AnomalyLOW
scripts/session-probe

This module performs targeted inspection of a local browser cookie database and persists authentication-session-adjacent presence and timestamp metadata to a local log file. While it does not exfiltrate raw cookie values or show any network activity in this fragment, the combination of (1) accessing session-related cookies, and (2) storing derived metadata persistently in a nonstandard application/agent log path is a meaningful privacy/security concern. The likelihood of overt malware behavior (e.g., exfiltration, persistence, command-and-control) cannot be confirmed from this single snippet, but the intent is plausibly recon/telemetry around authenticated state.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Aug 4, 2026, 11:27 PM
Package URL
pkg:socket/skills-sh/crazynomad%2Fskills%2Fflow-media%2F@41eafe1f6f1317c7813a25121b42273a9a2cd4769ac64fc76b67e5be325a1f29
Security Audit — socket — flow-media