harness-migration
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s behavior largely matches its migration purpose and shows no clear credential theft or exfiltration, but it relies on executing a freshly cloned toolchain from a personal GitHub repository and optionally installing that checkout globally. The local filesystem and daemon changes are significant yet mostly proportionate to migration, so this is better classified as a supply-chain and operational-risk skill rather than malware.
Confidence: 85%Severity: 66%
Audit Metadata