flomo-local-api

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/flomo_local_api.py

Best report choice: Report 3 (most complete and consistent). Improved assessment: This module is primarily a Flomo memo automation CLI, but it contains two high-sensitivity supply-chain/security red flags: (a) it harvests a local Flomo access token by scanning the user’s LevelDB/App storage, and (b) it embeds a hardcoded API secret used for request signing (MD5-based). Network activity appears constrained to flomoapp.com/api/v1, and there are no obvious classic malware behaviors in this snippet (no exec/subprocess/backdoor/external-domain exfiltration). However, the token harvesting + embedded secret combination makes it risky to distribute or include as a dependency without explicit user trust and security review.

Confidence: 70%Severity: 62%
Audit Metadata
Analyzed At
Mar 27, 2026, 04:22 AM
Package URL
pkg:socket/skills-sh/Undertone0809%2Fflomo-local-api-skill%2Fflomo-local-api%2F@40294a66573391e14d4d8a3872c4f3877b1e5c5a