vmos-edge-flowsmith

Warn

Audited by Socket on Aug 19, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

BENIGN for provenance and data flow, but HIGH RISK in use: the skill is internally consistent with VMOS Edge automation, uses vendor-documented local endpoints, and shows no clear exfiltration or malware behavior. The main concern is autonomy abuse because it explicitly supports large-scale account actions like bulk messaging, registration, and farming on real devices/accounts.

Confidence: 91%Severity: 78%
AnomalyLOW
references/syntax.md

No explicit malware payload is evidenced within the snippet (no reverse shell/process spawning or hardcoded real secrets). However, the configuration documents a high-capability automation workflow that can (a) capture screenshots, (b) read on-screen text, (c) manipulate device state, and most importantly (d) perform authenticated outbound HTTP requests that include a Bearer token and a phone number. Combined with unusually permissive/opaque httpRequest retry/success behavior, this creates a meaningful risk of privacy/data exfiltration or account/API abuse if the runtime variables and destinations are not strictly controlled. Treat as security-sensitive automation logic requiring strong scrutiny of TOKEN/PHONE sourcing and the real API endpoint/receiver.

Confidence: 46%Severity: 67%
Audit Metadata
Analyzed At
Aug 19, 2026, 09:28 PM
Package URL
pkg:socket/skills-sh/vmos-dev%2Fvmos-edge-skills%2Fvmos-edge-flowsmith%2F@b7d4d8a32d2eaddb667344e24cbbae1c8203a8a40fa8a966d75225de10a7f74c
Security Audit — socket — vmos-edge-flowsmith