harness-download
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s behavior largely matches its stated onboarding purpose, but it asks the agent to clone and execute mutable source from a personal GitHub repo, run install scripts, and propagate additional skills into agent directories without a packaged or verifiable release path. This is primarily a supply-chain and transitive-trust risk rather than clear malware or credential theft.
Confidence: 90%Severity: 82%
Audit Metadata