harness

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The harness purpose is coherent, and it does not introduce obvious credential theft or off-platform exfiltration. However, it intentionally feeds locally stored skill instructions into a general-purpose subagent with Bash/Write/Agent access and then runs project build scripts, creating meaningful prompt-injection and transitive execution risk disproportionate for a generic test harness unless the tested skills and repo are fully trusted.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Apr 26, 2026, 09:57 PM
Package URL
pkg:socket/skills-sh/even-realities%2Feverything-evenhub%2Fharness%2F@8e2df5b690b0470715e139a18a75ec8dda6a4db1
Security Audit — socket — harness