Claude Flow CLI

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s broad orchestration, hook, MCP, and command-execution footprint is generally aligned with its stated purpose, but it relies on repeatedly executing a mutable third-party CLI via npx @latest and exposes high-impact autonomous and execution capabilities without clear trust or endpoint boundaries. This looks more like a powerful external tool wrapper than a narrowly scoped skill; risk is mainly supply-chain and overbroad execution, not confirmed malware.

Confidence: 79%Severity: 66%
Audit Metadata
Analyzed At
May 10, 2026, 11:30 PM
Package URL
pkg:socket/skills-sh/ricable%2Fcli-skills-builder%2Fclaude-flow-cli%2F@070c03e056f247b4b0a5c1a33381f5c32bc671d4
Security Audit — socket — Claude Flow CLI