xiaobao-flow2api
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill’s capabilities mostly match its stated purpose as a Flow2API client wrapper, and its credential/file access is broadly proportionate. The main concern is trust and transparency: it forces use of a bundled CLI that reads API keys from `.env` and sends them to a configurable backend, without clear provenance or fixed official endpoint guarantees. Overall this is better classified as suspicious/medium risk than malicious.
Confidence: 80%Severity: 52%
Audit Metadata