xiaobao-flow2api

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s capabilities mostly match its stated purpose as a Flow2API client wrapper, and its credential/file access is broadly proportionate. The main concern is trust and transparency: it forces use of a bundled CLI that reads API keys from `.env` and sends them to a configurable backend, without clear provenance or fixed official endpoint guarantees. Overall this is better classified as suspicious/medium risk than malicious.

Confidence: 80%Severity: 52%
Audit Metadata
Analyzed At
Apr 2, 2026, 01:20 AM
Package URL
pkg:socket/skills-sh/xue-xiaobao%2Fxuexiaobao-skills%2Fxiaobao-flow2api%2F@8f47406bcecaf42427b35f426dbd434e4d458e84
Security Audit — socket — xiaobao-flow2api