flow-media
Audited by Socket on Aug 4, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the purpose is coherent, but the skill's footprint is high-trust because it installs an unofficial personal CLI and gives it access to an authenticated Google browser session to perform account-backed generation. Data appears intended for official Google Flow, not an obvious exfiltration service, so this is not confirmed malware; the main risk is credential/session exposure and supply-chain trust in third-party automation code.
This module performs targeted inspection of a local browser cookie database and persists authentication-session-adjacent presence and timestamp metadata to a local log file. While it does not exfiltrate raw cookie values or show any network activity in this fragment, the combination of (1) accessing session-related cookies, and (2) storing derived metadata persistently in a nonstandard application/agent log path is a meaningful privacy/security concern. The likelihood of overt malware behavior (e.g., exfiltration, persistence, command-and-control) cannot be confirmed from this single snippet, but the intent is plausibly recon/telemetry around authenticated state.