harness-synthesizer
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core purpose is plausible, but the skill includes explicit instructions to evade sensitive-path protections by writing in /tmp and copying into .claude/ via an unaudited script path. That bypass behavior is disproportionate to a harness-synthesis skill and is the main driver of risk; there is no notable external supply-chain component.
Confidence: 89%Severity: 79%
Audit Metadata