harness-synthesizer

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core purpose is plausible, but the skill includes explicit instructions to evade sensitive-path protections by writing in /tmp and copying into .claude/ via an unaudited script path. That bypass behavior is disproportionate to a harness-synthesis skill and is the main driver of risk; there is no notable external supply-chain component.

Confidence: 89%Severity: 79%
Audit Metadata
Analyzed At
May 15, 2026, 06:20 PM
Package URL
pkg:socket/skills-sh/baekenough%2Foh-my-customcode%2Fharness-synthesizer%2F@3e75322aeaae980ba41ec486846d7cba1971702b
Security Audit — socket — harness-synthesizer