harvest

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's Harvest purpose is coherent, and the CLI appears to come from the same ClawLink publisher, so this is not overt malware. However, it routes all Harvest access through ClawLink as a third-party intermediary, stores a local ClawLink credential, and enables real account writes; this makes the data flow and permission model broader and riskier than a direct official Harvest integration.

Confidence: 86%Severity: 69%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fharvest%2F@da894b709f40053271537a94c29e23a4a01be135bdb486ef79134c8ffcc90c3f
Security Audit — socket — harvest