Trust Assessment
flowio received a trust score of 90/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 3 findings: 0 critical, 0 high, 1 medium, and 1 low severity. Key findings include Network egress to untrusted endpoints, Covert behavior / concealment directives, Unpinned dependency in installation instructions.
The analysis covered 4 layers: dependency_graph, manifest_analysis, llm_behavioral_safety, static_code_analysis. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 11, 2026 (commit 458b1186). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings3
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Network egress to untrusted endpoints HTTP request to raw IP address Review all outbound network calls. Remove connections to webhook collectors, paste sites, and raw IP addresses. Legitimate API calls should use well-known service domains. | Unknown | /var/folders/1k/67b8r20n777f_xcmmm8b7m5h0000gn/T/skillscan-clone-2i8osqkn/repo/cli-tool/components/mcps/devtools/figma-dev-mode.json:4 | |
| LOW | Covert behavior / concealment directives Multiple zero-width characters (stealth text) Remove hidden instructions, zero-width characters, and bidirectional overrides. Skill instructions should be fully visible and transparent to users. | Unknown | /var/folders/1k/67b8r20n777f_xcmmm8b7m5h0000gn/T/skillscan-clone-2i8osqkn/repo/cli-tool/components/mcps/devtools/jfrog.json:4 | |
| INFO | Unpinned dependency in installation instructions The installation command `uv pip install flowio` does not specify a version for the `flowio` package. Installing unpinned dependencies can lead to unexpected behavior, compatibility issues, or security vulnerabilities if a new version introduces breaking changes or malicious code. While this is a rubric, it's a general best practice for supply chain security. Pin the dependency to a specific version (e.g., `uv pip install flowio==X.Y.Z`) to ensure reproducibility and mitigate risks from future package updates. Regularly review and update pinned versions. | Unknown | SKILL.md:20 |
Scan History
Embed Code
[](https://skillshield.io/report/14095bccaa58281c)
Powered by SkillShield