harness-setup

Warn

Audited by Socket on Jun 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core setup behavior is mostly coherent and the Codex CLI install path is official, but the skill also instructs transitive installation/update of arbitrary Claude plugins by `owner/repo`, extending trust beyond the stated setup scope. No direct credential theft or exfiltration is evident, so this is better classified as elevated supply-chain risk than malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 17, 2026, 11:42 AM
Package URL
pkg:socket/skills-sh/fockus%2Fclaude-skill-build%2Fharness-setup%2F@ce910b1f0f22cfc4c9766c5cccf46f298d9fd268fff91b1954956a2d2231b973
Security Audit — socket — harness-setup