jianying-harness
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s stated purpose and behavior are mostly coherent, and it includes strong safety constraints, but it critically relies on an external `jianying` CLI whose provenance is not clearly verifiable from official same-org sources. No direct exfiltration, installer chain, or overtly malicious behavior appears in the skill content, yet the unverifiable external binary dependency keeps overall risk high.
Confidence: 85%Severity: 74%
Audit Metadata