create-agent

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated purpose of creating Harness agents, so it is not clearly malicious. However, it normalizes high-impact agent configs: broad Bash/MCP permissions, credential forwarding to external MCP endpoints, ngrok/public MCP exposure, and autonomous actions with real-world effects. Main concern is security risk and scope expansion, not confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 13, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/harness%2Fharness-skills%2Fcreate-agent%2F@00b85ef2f26ab2e64e40b267fd33f54a8a2ecf02
Security Audit — socket — create-agent