electron

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main capabilities do match its stated Electron build/deploy purpose, and its use of electron-builder via npm appears legitimate. The concern is scope and operational trust: it hardcodes a production VPS/IP, assumes root-level deployment access, invokes an opaque local deploy script, runs deployment in the background, and performs real-world release actions including git push. This is coherent for a private project release skill, but it is high-impact and should only run in a tightly trusted environment with explicit user approval per deploy.

Confidence: 86%Severity: 69%
Audit Metadata
Analyzed At
Apr 22, 2026, 01:15 AM
Package URL
pkg:socket/skills-sh/endlessblink%2Fflow-state%2Felectron%2F@10c7733a9bc421811270436bfc67a07f38e26b57
Security Audit — socket — electron