setup-plaud-flutter
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is largely coherent with its stated purpose: mobile BLE/device SDK integration, local plugin setup, and Plaud API usage. Main concern is supply-chain trust: it asks the agent to use checked-in precompiled native binaries (.xcframework/.aar) distributed outside an official package registry, which are hard to verify from the provided evidence. Credential use is proportionate to the Plaud SDK/transcription purpose, and data flows go to Plaud/S3 rather than unrelated third parties. No confirmed malicious or stealth behavior is present.
Confidence: 89%Severity: 72%
Audit Metadata