harness-work
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly aligned with its stated purpose of autonomous implementation and task orchestration, and its Codex integration appears to reference an official OpenAI CLI rather than an unknown payload. However, it grants high-impact autonomous write/exec/git capabilities, can send prompts and diffs to an external CLI, and depends on unseen local/internal components (`scripts/review-ai-residuals.sh`, `harness-plan`). The main issue is scope and autonomy risk rather than confirmed malware or credential theft.
Confidence: 84%Severity: 58%
Audit Metadata