one-flow

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s workflow/orchestration features mostly match its stated purpose, but it depends on an unverified external `one` CLI that can execute authenticated cross-platform actions, read local/env data, and run embedded JS. The main risk is trust in that opaque runtime plus the skill’s ability to trigger real-world actions across connected services.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 18, 2026, 07:47 AM
Package URL
pkg:socket/skills-sh/picahq%2Fcli%2Fone-flow%2F@8359c0219f3d785078dbf335dd735a3cf3b4f7f3
Security Audit — socket — one-flow