create-connector

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s behavior is mostly aligned with its stated purpose of creating Harness connectors, and it uses secret references rather than harvesting local credentials. The main concern is install/execution trust: the required Harness MCP v2 path uses npx and documentation links V2 source to a personal GitHub account instead of a clearly same-org official repo, while also receiving a HARNESS_API_KEY. No clear malicious data exfiltration or hidden behavior is present, but the trust chain is weaker than expected for a credential-bearing enterprise integration skill.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 12:13 PM
Package URL
pkg:socket/skills-sh/harness%2Fharness-skills%2Fcreate-connector%2F@c73c7e5bca94fe7a33fd8174a3fd4426d0617bf5
Security Audit — socket — create-connector