adaptive-harness
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core project-scanning and local profile-management behavior is plausible, but the skill crosses the line by explicitly instructing the agent to bypass Claude sensitive-path protections and audit visibility using `/tmp` plus Bash. There is no external exfiltration or third-party install chain, so this is not confirmed malware, but the guardrail-evasion guidance makes the skill high risk for local integrity and policy bypass.
Confidence: 89%Severity: 78%
Audit Metadata