flow-remediator-publisher

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated remediation/publishing purpose, and there is no clear malware behavior or deceptive installer. However, it handles sensitive flow data and API keys, can perform remote inserts, and allows both LLM and MCP traffic to be routed to environment-defined endpoints whose ownership cannot be verified from the skill text, creating meaningful data-flow and trust risk.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Mar 20, 2026, 08:57 AM
Package URL
pkg:socket/skills-sh/tiangong-lca%2Fskills%2Fflow-remediator-publisher%2F@f43f2fb7df3f2b806018f122cfe90c09c9ef94a1