when-building-backend-api-orchestrate-api-development
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is broadly aligned with backend API delivery, but it combines unpinned external tool execution (`npx claude-flow`), extensive command execution, offensive security tooling, and autonomous production deployment/traffic shifting. This looks more like a high-impact operational workflow than simple documentation; risk is driven by broad authority and mutable execution trust, not by confirmed credential theft or overt malware.
Confidence: 86%Severity: 76%
Audit Metadata