harness-migration

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s behavior largely matches its migration purpose and shows no clear credential theft or exfiltration, but it relies on executing a freshly cloned toolchain from a personal GitHub repository and optionally installing that checkout globally. The local filesystem and daemon changes are significant yet mostly proportionate to migration, so this is better classified as a supply-chain and operational-risk skill rather than malware.

Confidence: 85%Severity: 66%
Audit Metadata
Analyzed At
Sep 3, 2026, 08:16 AM
Package URL
pkg:socket/skills-sh/fairladyz625%2Fharness-anything%2Fharness-migration%2F@06a35d4cd98136d5ba3c1e4099202e15feed3fb50224f2297ea21093671245f5
Security Audit — socket — harness-migration